An Unlearning Audit of 263 Released Checkpoints Finds 47 Move Past Their Own Seed Spread Just by Refitting Batch-Norm Statistics
arXiv 2609.11490 (submitted 10 Sep 2026) notes that unlearning verdicts are read off numbers published by an unlearned model and its retrained reference, and both also ship batch-normalization statistics that no gradient step wrote and no release records. Refitting those statistics on kept data at bit-identical weights moves 47 of 221 released checkpoints past the spread their own release's seeds show, sometimes inside a method whose average does not move. The cause is not removed data surviving in the state: swapping kept records for removed ones inside a fixed fitting pool barely moves a published cell, while drift between the shipped state and any refit does track it, and twelve published verdicts flip.
↳ Follow the thread