Models Designed to Forget: Machine Unlearning via Key Deletion

summary

Video file (mp4)

The gist

Machine unlearning is rapidly becoming a practical requirement, driven by privacy regulations, data errors, and the need to remove harmful or corrupted training samples.

In short

The paper proposes MUNKEY, a method for machine unlearning by design that integrates forgetting directly into model training. It decouples instance data into an external memory bank using learnable exemplar tokens. This allows for zero-shot forgetting—removing specific data influence without retraining—while maintaining model performance through pathway sensitivity checks.

Key concepts

Unlearning by Design
Instead of removing data after training, this approach anticipates forgetting during the initial training process. It involves structuring the model so that instance-specific knowledge is stored externally rather than being permanently entangled in the main network weights, making removal straightforward.
MUNKEY (Machine UNlearning via KEY Deletion)
This is a method that stores each training example's unique information as a learnable token. By associating an image with a specific key and a learnable value, the model learns to rely on these external tokens for instance details, allowing specific data influence to be deleted by simply removing those tokens from memory.
Pathway Sensitivity Score (Ps)
This score measures how reliant the model is on different parts of its architecture—like image processing versus token processing. It ensures that when data is forgotten, the model doesn't collapse entirely by checking performance after replacing one pathway with null tokens, ensuring both utility and robustness.
Exemplar Memory Bank (M)
This is an external storage system where each training instance is mapped to a unique key-value pair. The keys are derived from the input data, and the values are learnable tokens. This bank acts as an organized repository for all specific instance information, separate from the core model weights.

Terminology used across episodes

This episode discusses

The paper

Models Designed to Forget: Machine Unlearning via Key Deletion · Read on arXiv

Department of Computer Science, ETH Zurich

Transcript

Introduction to the show: ident: AI Radio. Generated commentary on the latest Artificial Intelligence papers.

Tom: Today's paper: "Models Designed to Forget".

Jane: Machine unlearning is rapidly becoming a practical requirement, driven by privacy regulations, data errors, and the need to remove harmful or corrupted training samples.

Tom: First, who's behind it and why it matters.

Title and authors: Tom: So we’re starting by looking at the title of "Models Designed to Forget: Machine Unlearning via Key Deletion," and it immediately tells us that these authors aren't just trying to patch up old unlearning methods; they are actually designing the model structure from the beginning to handle forgetting. The list of authors includes Laguna, Gonçalves, Vandenhirtz, Ryser, Cannistraci, and Vogt.

Jane: And what’s significant about this framing is how they propose moving away from post-hoc techniques that involve updating parameters during unlearning requests. They are suggesting that forgetting should be an inherent feature of the model architecture itself.

Lu: The authors support this idea by showing how separating the memory bank allows for a simple set-theoretic operation—just deleting an entry—to achieve zero-shot forgetting without needing any retraining or weight updates, which is quite a significant move.

Meng: It makes sense that they are shifting the responsibility of memorization away from the static weights and onto this externalized memory structure, especially when you consider deployment scenarios where data privacy needs change frequently.

Lalam: From what I’m seeing, the authors really focus on how this architecture allows for privacy-centric deployment by eliminating the necessity of storing raw samples or labels at the exact moment you need to forget something.

Tom: Right, and they back this up with recent findings that show visual memories can be used effectively even with billion-scale datasets, which gives them strong support for this entire approach.

Jane: It suggests that by using memory-augmented structures for the task of forgetting, they are creating a new category of models that are naturally compliant with changing privacy requirements.

Lu: I think the authors also point out that using external or decoupled memories has been explored before for things like boosting predictive performance or improving few-shot efficiency, so they are building on previous research in that area.

Meng: So, what they’re doing is taking those existing memory concepts and applying them specifically to the inverse task of data deletion, which is a clever way to use the technology.

Lalam: It really shows how foundational AI concepts can be repurposed to solve very specific constraints, like regulatory demands for data removal.

The paper's summary: Tom: So, summarizing "Models Designed to Forget: Machine Unlearning via Key Deletion," the authors propose a memory-augmented transformer where they decouple instance-specific memorization from the model weights by associating each piece of data with a learnable exemplar token.

Jane: Basically, they train the model so it learns to depend on this external bank of tokens for specific details, meaning when you want to forget something, you just remove that specific identifier from that bank.

Lu: The training involves injecting these tokens into the input sequence alongside image patches and optimizing both the main network parameters and these exemplar tokens at the same time using a cross-entropy loss.

Meng: The inference side is where things get interesting because for a new query, instead of looking at its original token, the model retrieves a set of nearest neighbors from this external memory bank based on key similarities.

Lalam: And then the final prediction isn't just one output; it’s an ensemble prediction calculated by weighting the logits from those retrieved tokens, which gives us a more stable final answer.

Tom: It really boils down to having the model look at its context and ask, "Which stored examples are most relevant right now?" which is a different way of making a decision compared to relying only on fixed internal weights.

Jane: This mechanism directly tackles the problem of knowledge entanglement in standard architectures by moving that memorization out into this external structure, which is what they call unlearning by design.

Lu: It suggests that the model doesn't need to keep every detail locked away in its weights; instead, it can use a flexible, accessible memory bank for instance-specific information when needed.

Meng: From an engineering standpoint, this means that as long as we have a reliable way to manage that external bank and the retrieval process works well, we can separate the model's core parameters from the data itself.

Lalam: I think this moves AI development toward systems where data is treated more like a dynamic resource instead of just static input for training.

The paper's improvements: Tom: Now let’s talk about how they improve upon existing ideas, and they introduce a stochastic pathway dropout to stop the model from becoming too reliant on just one way of processing the data.

Jane: And that dropout is combined with a Bernoulli sampling of a retrieval state, which decides whether the model uses the specific instance token or groups together neighboring tokens from memory. This adds another level of controlled variability to how it accesses that external memory.

Lu: The paper also introduces a Pathway Sensitivity Score, Ps, which helps them check the balance by testing performance when one pathway is replaced by learned null tokens,.

Meng: That Ps score is important for validation because it lets them see if the model actually keeps its utility while making sure both pathways—the raw image patches and the learned tokens—are contributing meaningfully.

Lalam: They also mention an ensembling strategy as being the most robust way to maintain this pathway balance while keeping that Average Gap low, suggesting ensembling is a critical structural element for controlling how well forgetting operates.

Tom: So when you put all those elements together, they are giving us a controlled mechanism to make sure that when we delete something, the model stays useful and accurate for what it was supposed to retain.

Jane: This control mechanism makes the process of removing data much more predictable than just letting the system wander around randomly during training.

Lu: The fact that they tested different key encoders like ViT, DINO-v2, and CLIP4 shows that this system is quite adaptable and doesn't need label information embedded in those keys to work correctly.

Meng: That adaptability is important because it means we aren't tied to one specific visual encoder for this unlearning technique; we can pick the best tool for the job.

Conclusion: Tom: So, wrapping up "Models Designed to Forget: Machine Unlearning via Key Deletion," the main implication is that we can now perform instance-specific data removal in a way that is both extremely fast and keeps privacy intact.

Jane: This capability means high-stakes environments, like clinical studies, can finally use AI with confidence knowing they have a surgical tool to surgically remove specific training examples without hurting the overall model performance on the data it keeps.

Lu: The structural flexibility shown across different key encoders opens up interesting avenues for how we can manage knowledge externally in even more complex AI systems.

Meng: For me, the practical impact is realizing that unlearning isn't just a theoretical exercise anymore; it’s a tool we can deploy to meet real operational needs in regulated industries.

Lalam: I think the overall direction of this work encourages us to treat data as a dynamic resource within AI systems rather than just static training input for future development.

Tom: Absolutely, so that’s where we are heading next, and I’m really looking forward to seeing how these design principles apply to other areas of AI research.

Jane: We definitely have a lot more interesting papers coming up, so stick with us as we keep exploring this fascinating space.

More episodes

← Home