LLM Unlearning Evaluation with TRIAGE

📅 2026-09-26
📈 Citations: 0
✨ Influential: 0
📄 PDF
🤖 AI Summary
Existing evaluations of large language model unlearning focus solely on behavioral performance, lacking internal insights into parameter changes and their effects on associated knowledge. To address this limitation, this work proposes TRIAGE, the first representation-based internal auditing framework for unlearning evaluation. TRIAGE leverages Fisher information and diagonal Hessian approximations to quantify parameter sensitivity, and introduces a tripartite partition metric to assess the retention of semantically adjacent knowledge. Furthermore, it categorizes parameter updates into four distinct patterns to reveal mechanistic differences among unlearning algorithms. Extensive experiments across twelve methods and multiple benchmarks demonstrate that unlearning effects are significantly influenced by model architecture and data characteristics. By providing an internal perspective, this framework effectively complements traditional behavior-centric evaluation paradigms.
📝 Abstract
Large language models can memorize private or harmful information, motivating machine unlearning methods that remove targeted knowledge while preserving other capabilities. However, existing evaluations rely primarily on behavioral benchmarks, which assess \emph{whether} a model appears to forget but provide limited insight into \emph{how} unlearning changes the model or affects related knowledge. We introduce \textit{TRIAGE} (\textit{Tripartite Representation-internal Introspection for Adjacency Gap Evaluation}), a benchmark-agnostic evaluation framework for characterizing these changes. TRIAGE uses diagonal approximations of the Fisher information and Hessian to measure changes in parameter sensitivity and local curvature, and utilizes a Forget / \emph{Adjacent-Retain} / \emph{Generic-Retain} partition to quantify an \emph{adjacency gap} in semantically related knowledge. Based on the magnitude and distribution of these changes, TRIAGE further classifies each algorithm's update as \emph{no-op}, \emph{partially localized}, \emph{collateral dominant}, or \emph{globally destructive}. Across 12 unlearning methods, four language models, and the WMDP, TOFU, and MUSE benchmarks, we find that methods with similar behavioral forgetting can produce substantially different internal changes and patterns of collateral damage. These signatures also vary across models and benchmarks, indicating that the effects of unlearning are not determined solely by the unlearning algorithm. TRIAGE can be applied alongside existing unlearning benchmarks to complement behavioral evaluation with a model-internal view of how unlearning reshapes the model's parameter space and affects retained knowledge.
Problem

Research questions and friction points this paper is trying to address.

LLM Unlearning
Evaluation
Machine Unlearning
Internal Representation
Collateral Damage
Innovation

Methods, ideas, or system contributions that make the work stand out.

Machine Unlearning
Internal Representation Analysis
Fisher Information
Adjacency Gap
Evaluation Framework
🔎 Similar Papers