acceptodds
Under review as a conference paper at ICLR 2027

Opting Out Should Not Be Detectable: Fresh-Identity Indistinguishability for Identity Unlearning

Abstract

Unlearning is evaluated by what a model can still retrieve, not by whether the deletion request is visible. We define fresh-identity indistinguishability (FII) relative to an adversary class and test for its violation with the paired detection-AUC gap between a released encoder and its same-seed retrain oracle on identical identities and splits: a positive gap witnesses a violation. At 100 opted-out Market-1501 identities, an adversary holding no training image reaches AUC 0.802 +/- 0.020 against the oracle's 0.622 +/- 0.081 (gap +0.180, 5/5 seeds), naming 17% of requesters at a 1% false-accusation rate; one unknowingly holding some training images reaches 0.968 +/- 0.008 against 0.717 +/- 0.019 (gap +0.252, TPR 0.588). The mark replicates on ResNet-18 and ConvNeXt-T encoders and on CUHK03-NP, and a detector fit on one opt-out set reads it off disjoint identities (0.801 against 0.591 on their oracle, 20 of 20 pairs), off other architectures and off the other dataset, and it stays detectable through a retrieval service that returns only top-10 ranks. It is a tighter-than-never-seen cluster: forgotten identities remain more self-similar than people the model never saw. Across 39 operating points of five unlearning methods, none keeps retain mAP at or above 0.95, brings forget mAP to at most 0.02 above the oracle's and passes the mixed-adversary FII test; the methods that preserve utility best, neggrad_plus and finetune, leak on every seed under the mixed adversary. Our evidence is three academic benchmarks, not face retrieval.

Then back it, or bet against it.

Related papers

Open the market on this paper to see 7 more related papers.