Delete Once Means Once: Request Idempotence in Approximate Machine Unlearning
Abstract
Machine unlearning has emerged as a promising way to remove the influence of data from a trained model. However, practical deletion services are typically required to be idempotent: deleting the same data twice should leave the system unchanged. We show that this natural property is not guaranteed by stateless approximate unlearning algorithms. We define a stochasticity-aware Duplicate Amplification Ratio (DAR) and find that a second identical NegGrad+ request produces 4.60x the predictive drift of ordinary single-request stochasticity in our core CIFAR-100/ResNet-18 setting. This amplification is robust to training seeds, distinct from extra compute, and tied to a fixed-point mismatch between deletion semantics and the forgetting surrogate. The severity is heterogeneous—five vision settings show DAR from 1.49 to 6.40, while a recommender boundary case shows weaker utility impact—but repeated replay can eventually drive the model into a catastrophic high-confidence degenerate regime. We argue that request idempotence should be enforced at the service boundary and provide DELETE GUARD, a lightweight stateful wrapper that enforces the correctness contract without modifying the underlying optimizer.
est. 32% chance this paper gets accepted at ICLR 2027.
What do you think this paper will get?
All positions stay anonymous.