Deletion Must Reach Every Copy: Federated Execution of Unlearning
Abstract
Federated unlearning (FU) removes the influence of withdrawn data from a model trained by clients that never centralize it. FU faces a distinctive obstacle: federated training leaves persistent copies on devices and at the edge, and each copy an edit misses returns the withdrawn content through later aggregation. Current methods edit the server's global model, and they certify that model rather than the copies a request governs. To address these, we first establish unlearning as an operation on the federated state: the server transcript does not determine which parties a request affects, and holder-local readings do. We then design LOCUS, a Locality-Ordered Correction of Unlearned State framework that executes each step where its evidence lives. Within this framework, Influence Localization has each holder report the retention cost of a candidate correction and what its copy still carries. Correction Propagation then delivers one minimum-norm correction to every holder in that closure and gates a copy out of aggregation until it acknowledges. In addition, Divided Verification assigns removal, retention and application checks to the parties that observe them and binds them into one certificate. Across two benchmarks, three deployments, five unlearning objectives and seven published FU protocols, LOCUS corrects 92–99% of the governed copies, while server-side execution corrects none and the protocols at most 60%. For example, on TOFU with Llama-3.2-1B, LOCUS with NPO corrects 95% of the copies and preserves the erasure throughout a 300-round continuation, whereas server-side NPO loses it after 17 rounds and Oblivionis, the longest-surviving published protocol, after 73 rounds.
Then back it, or bet against it.
Related papers
Open the market on this paper to see 7 more related papers.