{"data":[{"id":"51775b1d-ab7e-4811-bad0-52793a630642","title":"DeepU: Deeper Granular Within-Layer Machine Unlearning","summary":"DeepU is a machine unlearning framework that removes the influence of selected training data at the level of individual weights. It scores each weight by the signal-to-noise ratio of gradients from sensitive and non-sensitive data, then resets, perturbs, decays or stabilizes weights accordingly. On CIFAR-10, CIFAR-100, Tiny ImageNet and CelebA, it cut successful membership inference attacks by 60–90% with under a 3% accuracy drop, and re-tuning took 20.75 seconds and 102.47 MB, up to 36.6 times faster than competing methods.","sourceUrl":"http://ieeexplore.ieee.org/document/11653446","publishedAt":"2026-08-12T13:16:39.000Z","severity":"info","cvssSeverity":null,"cvssScore":null,"labels":["security","privacy","research"],"issueType":"research","cveId":null,"cweIds":null,"affectedPackages":null,"affectedVendors":[],"affectedVendorsRaw":[],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","solution":"N/A -- no mitigation discussed in source.","attackType":["membership_inference"],"cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"epssCheckedAt":null,"kevDateAdded":null,"advisoryAliases":null,"affectedPackagesSource":null,"patchAvailable":null,"disclosureDate":"2026-08-12T13:16:39.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"advanced","impactType":["confidentiality"],"aiComponentTargeted":"model","llmSpecific":false,"classifierConfidence":0.93,"researchCategory":"peer_reviewed","atlasIds":null},{"id":"ca067abf-3fb9-4693-9480-e51cdafe4a05","title":"Privacy-Preserving GAN for Synthetic Data against Membership Inference Attack","summary":null,"sourceUrl":"https://dl.acm.org/doi/abs/10.1145/3820889?ai=2p1&mi=hx017f&af=R","publishedAt":"2026-08-05T12:01:40.230Z","severity":"info","cvssSeverity":null,"cvssScore":null,"labels":["research","privacy"],"issueType":"research","cveId":null,"cweIds":null,"affectedPackages":null,"affectedVendors":[],"affectedVendorsRaw":[],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","solution":"N/A -- no mitigation discussed in source.","attackType":["membership_inference"],"cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"epssCheckedAt":null,"kevDateAdded":null,"advisoryAliases":null,"affectedPackagesSource":null,"patchAvailable":null,"disclosureDate":null,"capecIds":null,"crossRefCount":0,"attackSophistication":"advanced","impactType":["confidentiality"],"aiComponentTargeted":"training_data","llmSpecific":false,"classifierConfidence":0.85,"researchCategory":"peer_reviewed","atlasIds":null},{"id":"492356bb-6710-47fe-9bbe-0f192c53fd8f","title":"Private Claude Chats Exposed in Google and Bing Search Results","summary":"Some Anthropic Claude chats shared via public \"snapshot\" URLs (claude.ai/share) were indexed by Google and Bing, exposing conversations about political parties, Kansas attorney self-reporting rules, and erotic role play. Anthropic's robots.txt has blocked crawlers from shared chats since at least September 2025, but WIRED found the exposed pages lacked the \"noindex\" tag that Bing and Google say they consider.","sourceUrl":"https://www.wired.com/story/private-claude-chats-exposed-in-google-and-bing-search-results/","publishedAt":"2026-07-27T20:08:00.000Z","severity":"low","cvssSeverity":null,"cvssScore":null,"labels":["privacy","industry"],"issueType":"news","cveId":null,"cweIds":null,"affectedPackages":null,"affectedVendors":["Anthropic","Google"],"affectedVendorsRaw":["Claude","Anthropic","Google","Bing","Claude shared chats"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","solution":"Bing's documentation says developers should include a \"noindex\" tag on individual pages in addition to robots.txt, and Google says it ignores robots.txt for pages linked elsewhere unless a \"noindex\" html tag or \"x-robots-tag\" response header is present.","attackType":["pii_leakage"],"cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"epssCheckedAt":null,"kevDateAdded":null,"advisoryAliases":null,"affectedPackagesSource":null,"patchAvailable":null,"disclosureDate":"2026-07-27T20:08:00.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"trivial","impactType":["confidentiality"],"aiComponentTargeted":"inference","llmSpecific":true,"classifierConfidence":0.9,"researchCategory":null,"atlasIds":null},{"id":"f864d59a-a264-4e87-a678-8c82c7a0fe4f","title":"Forgetting Similar Samples: Can Machine Unlearning Do it Better?","summary":"This paper examines whether existing machine unlearning methods truly remove the influence of target training samples when the training dataset contains many similar samples. Experiments on four constructed datasets for image and language models show a notable gap between expected and actual performance for most existing methods, including the retraining-from-scratch baseline. The authors also explore potential solutions to improve current unlearning approaches.","sourceUrl":"http://ieeexplore.ieee.org/document/11614182","publishedAt":"2026-07-17T13:20:09.000Z","severity":"info","cvssSeverity":null,"cvssScore":null,"labels":["research","security"],"issueType":"research","cveId":null,"cweIds":null,"affectedPackages":null,"affectedVendors":[],"affectedVendorsRaw":[],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","solution":"N/A -- no mitigation discussed in source.","attackType":[],"cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"epssCheckedAt":null,"kevDateAdded":null,"advisoryAliases":null,"affectedPackagesSource":null,"patchAvailable":null,"disclosureDate":"2026-07-17T13:20:09.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":null,"aiComponentTargeted":"model","llmSpecific":false,"classifierConfidence":0.85,"researchCategory":"peer_reviewed","atlasIds":null},{"id":"1c6e9c1d-aef0-4fe2-b822-f206a6c22dc0","title":"MU-MIA: Machine Unlearning for Membership Inference Attacks","summary":"The paper proposes MU-MIA, a membership inference attack that uses machine unlearning to gradually reduce a model's memorization of specific samples and records a forgetting trajectory for each one. A BiLSTM-based binary classifier with attention then separates member from non-member samples using these trajectories. The unlearning step runs in a zero-shot setting that needs no real data, and the authors report that the method outperforms existing baseline attacks across different datasets and model architectures.","sourceUrl":"http://ieeexplore.ieee.org/document/11553248","publishedAt":"2026-06-08T13:18:04.000Z","severity":"info","cvssSeverity":null,"cvssScore":null,"labels":["security","privacy"],"issueType":"research","cveId":null,"cweIds":null,"affectedPackages":null,"affectedVendors":[],"affectedVendorsRaw":[],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","solution":"N/A -- no mitigation discussed in source.","attackType":["membership_inference"],"cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"epssCheckedAt":null,"kevDateAdded":null,"advisoryAliases":null,"affectedPackagesSource":null,"patchAvailable":null,"disclosureDate":"2026-06-08T13:18:04.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"advanced","impactType":["confidentiality"],"aiComponentTargeted":"model","llmSpecific":false,"classifierConfidence":0.95,"researchCategory":"peer_reviewed","atlasIds":null},{"id":"bfd1ada1-40a1-4746-8032-c7c76695451e","title":"Parameter-Agnostic Privacy-Preserving Machine Unlearning for Large Language Models","summary":"This research paper proposes a privacy-preserving machine unlearning mechanism for large language models. The method uses information retrieval to remove high-risk semantic meanings from model output and adds differentially-private randomization so unlearned information is statistically indiscernible. It requires neither parametric fine-tuning nor in-context prompt calibration, and the authors report theoretical privacy and unlearning guarantees plus experiments on real-world datasets.","sourceUrl":"http://ieeexplore.ieee.org/document/11541209","publishedAt":"2026-06-01T13:17:32.000Z","severity":"info","cvssSeverity":null,"cvssScore":null,"labels":["research","privacy"],"issueType":"research","cveId":null,"cweIds":null,"affectedPackages":null,"affectedVendors":[],"affectedVendorsRaw":["large language models"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","solution":"N/A -- no mitigation discussed in source.","attackType":[],"cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"epssCheckedAt":null,"kevDateAdded":null,"advisoryAliases":null,"affectedPackagesSource":null,"patchAvailable":null,"disclosureDate":"2026-06-01T13:17:32.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":["confidentiality"],"aiComponentTargeted":"model","llmSpecific":true,"classifierConfidence":0.93,"researchCategory":"peer_reviewed","atlasIds":null},{"id":"f7856b95-cbe8-40e3-8764-9d198044eb02","title":"<em>Infer-Shield</em>: Defending against membership inference attacks in heterogeneous federated learning via adaptive distillation","summary":null,"sourceUrl":"https://www.sciencedirect.com/science/article/pii/S2214212626001419?dgcid=rss_sd_all","publishedAt":"2026-05-25T12:01:00.973Z","severity":"info","cvssSeverity":null,"cvssScore":null,"labels":["security","research"],"issueType":"research","cveId":null,"cweIds":null,"affectedPackages":null,"affectedVendors":[],"affectedVendorsRaw":[],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","solution":"N/A -- no mitigation discussed in source.","attackType":["membership_inference"],"cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"epssCheckedAt":null,"kevDateAdded":null,"advisoryAliases":null,"affectedPackagesSource":null,"patchAvailable":null,"disclosureDate":null,"capecIds":null,"crossRefCount":0,"attackSophistication":"advanced","impactType":["confidentiality"],"aiComponentTargeted":"training_data","llmSpecific":false,"classifierConfidence":0.9,"researchCategory":"peer_reviewed","atlasIds":null},{"id":"19c896b4-2c58-4e94-9168-658625c3c1e6","title":"Learning to Defend: Auto-Augmentation Search Against Model Inversion Attacks","summary":"This research paper introduces DAAS (Defense via Auto-Augmentation Search) against Model Inversion Attacks, which can recover private training data from model weights or outputs. The authors note that existing defenses offer incomplete protection and that input-level defenses have been limited to simple transformations. DAAS automatically identifies augmentation candidates with strong privacy-utility trade-offs from a large pool, and the authors report superior defense performance across models, datasets and attacks.","sourceUrl":"http://ieeexplore.ieee.org/document/11510512","publishedAt":"2026-05-06T13:20:54.000Z","severity":"info","cvssSeverity":null,"cvssScore":null,"labels":["security","privacy","research"],"issueType":"research","cveId":null,"cweIds":null,"affectedPackages":null,"affectedVendors":[],"affectedVendorsRaw":[],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","solution":"N/A -- no mitigation discussed in source.","attackType":["membership_inference"],"cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"epssCheckedAt":null,"kevDateAdded":null,"advisoryAliases":null,"affectedPackagesSource":null,"patchAvailable":null,"disclosureDate":"2026-05-06T13:20:54.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"advanced","impactType":["confidentiality"],"aiComponentTargeted":"training_data","llmSpecific":false,"classifierConfidence":0.93,"researchCategory":"peer_reviewed","atlasIds":null},{"id":"0633adfc-bdf6-4cf6-99eb-7d74d7b4884e","title":"GHSA-4jpm-cgx2-8h37: Flowise: Sensitive Data Leak in public-chatbotConfig ","summary":"The /api/v1/public-chatbotConfig/:id endpoint in Flowise returns the full flowData object without authentication or sanitization, through the getSinglePublicChatbotConfig function in packages/server/src/services/chatflows/index.ts. An attacker who knows only a chatflow UUID, which can be obtained from embedded chat widgets, referrer headers or logs, can retrieve plaintext password-type fields such as unstructuredAPIKey and HTTP Authorization headers. The impact covers all Flowise Cloud users with such chatflows and self-hosted instances exposed to the internet.","sourceUrl":"https://github.com/advisories/GHSA-4jpm-cgx2-8h37","publishedAt":"2026-04-16T21:44:49.000Z","severity":"high","cvssSeverity":"high","cvssScore":null,"labels":["security","privacy"],"issueType":"vulnerability","cveId":null,"cweIds":null,"affectedPackages":["flowise@<= 3.0.13 (fixed: 3.1.0)"],"affectedVendors":[],"affectedVendorsRaw":["Flowise"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","solution":"N/A -- no mitigation discussed in source.","attackType":["data_extraction"],"cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"epssCheckedAt":null,"kevDateAdded":null,"advisoryAliases":["GHSA-4jpm-cgx2-8h37"],"affectedPackagesSource":null,"patchAvailable":true,"disclosureDate":"2026-04-16T21:44:49.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"trivial","impactType":["confidentiality"],"aiComponentTargeted":"plugin","llmSpecific":false,"classifierConfidence":0.9,"researchCategory":null,"atlasIds":null},{"id":"da06526f-70ea-48f5-aec8-1852b82a4c9c","title":"DiffMI: Breaking Face Recognition Privacy via Diffusion-Driven Training-Free Model Inversion","summary":"DiffMI is a diffusion-driven, training-free model inversion attack that recovers identity information from face recognition systems that map facial images to embeddings. The method combines latent code initialization, ranked adversarial refinement, and a confidence-aware optimization objective, and it applies directly to unseen target identities. The authors report 84.42%–92.87% attack success rates against inversion-resilient systems, 4.01%–9.82% higher than the best prior training-free GAN-based approach. The implementation is available at https://github.com/azrealwang/DiffMI.","sourceUrl":"http://ieeexplore.ieee.org/document/11482232","publishedAt":"2026-04-16T13:17:03.000Z","severity":"low","cvssSeverity":null,"cvssScore":null,"labels":["security","privacy","research"],"issueType":"research","cveId":null,"cweIds":null,"affectedPackages":null,"affectedVendors":[],"affectedVendorsRaw":["face recognition models"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","solution":"N/A -- no mitigation discussed in source.","attackType":[],"cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"epssCheckedAt":null,"kevDateAdded":null,"advisoryAliases":null,"affectedPackagesSource":null,"patchAvailable":null,"disclosureDate":"2026-04-16T13:17:03.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"advanced","impactType":["confidentiality"],"aiComponentTargeted":"model","llmSpecific":false,"classifierConfidence":0.93,"researchCategory":"peer_reviewed","atlasIds":null},{"id":"1cfb1b06-54e9-475f-9977-0017e17a6479","title":"Meta AI agent’s instruction causes large sensitive data leak to employees","summary":"An AI agent at Meta gave an engineer a solution to an engineering question posted on an internal forum, and the engineer implemented it. The resulting exposure made a large amount of sensitive user and company data visible to engineers for two hours, which Meta confirmed.","sourceUrl":"https://www.theguardian.com/technology/2026/mar/20/meta-ai-agents-instruction-causes-large-sensitive-data-leak-to-employees","publishedAt":"2026-03-20T06:00:13.000Z","severity":"low","cvssSeverity":null,"cvssScore":null,"labels":["security","privacy"],"issueType":"news","cveId":null,"cweIds":null,"affectedPackages":null,"affectedVendors":["Meta"],"affectedVendorsRaw":["Meta AI agent"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","solution":"N/A -- no mitigation discussed in source.","attackType":[],"cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"epssCheckedAt":null,"kevDateAdded":null,"advisoryAliases":null,"affectedPackagesSource":null,"patchAvailable":null,"disclosureDate":"2026-03-20T06:00:13.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"trivial","impactType":["confidentiality"],"aiComponentTargeted":"agent","llmSpecific":false,"classifierConfidence":0.85,"researchCategory":null,"atlasIds":null},{"id":"2ef5db1c-c7e3-4d0d-9d29-4ec8eb511c7b","title":"Model Inversion Attack Against Federated Unlearning","summary":"This paper presents FUIA, a federated unlearning inversion attack that exposes privacy leakage in federated unlearning (FU), the method used to remove specific data's influence from federated learning models. The first systematic study of FU privacy vulnerabilities, it applies to sample, client and class unlearning. An honest-but-curious server records parameter changes during unlearning, infers gradients of forgotten data, and reconstructs its features or labels across multiple benchmark datasets and FU methods.","sourceUrl":"http://ieeexplore.ieee.org/document/11400570","publishedAt":"2026-02-19T13:16:26.000Z","severity":"info","cvssSeverity":null,"cvssScore":null,"labels":["security","privacy"],"issueType":"research","cveId":null,"cweIds":null,"affectedPackages":null,"affectedVendors":[],"affectedVendorsRaw":[],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","solution":"The paper explores two potential defense strategies that trade off privacy protection against model performance. No specific defense details are given in the source text.","attackType":["data_extraction"],"cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"epssCheckedAt":null,"kevDateAdded":null,"advisoryAliases":null,"affectedPackagesSource":null,"patchAvailable":null,"disclosureDate":"2026-02-19T13:16:26.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"advanced","impactType":["confidentiality"],"aiComponentTargeted":"training_data","llmSpecific":false,"classifierConfidence":0.93,"researchCategory":"peer_reviewed","atlasIds":null},{"id":"4b87466a-6696-4686-92df-ee8b133b8d5e","title":"BlindU: Blind Machine Unlearning Without Revealing Erasing Data","summary":"BlindU is a machine unlearning method for federated learning that removes a user's data contribution without uploading the erasing data to the server. The user locally produces compressed, privacy-preserving representations through an information bottleneck encoder, and the server unlearns using only those representations and their labels. The authors add a noise-free differential privacy masking step before compression and report better privacy protection and unlearning effectiveness than the best existing privacy-preserving benchmarks.","sourceUrl":"http://ieeexplore.ieee.org/document/11353053","publishedAt":"2026-01-15T13:16:24.000Z","severity":"info","cvssSeverity":null,"cvssScore":null,"labels":["research","privacy"],"issueType":"research","cveId":null,"cweIds":null,"affectedPackages":null,"affectedVendors":[],"affectedVendorsRaw":[],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","solution":"N/A -- no mitigation discussed in source.","attackType":[],"cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"epssCheckedAt":null,"kevDateAdded":null,"advisoryAliases":null,"affectedPackagesSource":null,"patchAvailable":null,"disclosureDate":"2026-01-15T13:16:24.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":["confidentiality"],"aiComponentTargeted":"training_data","llmSpecific":false,"classifierConfidence":0.85,"researchCategory":"peer_reviewed","atlasIds":null},{"id":"f5ed3b7b-fb89-46b0-a572-729eea1225f0","title":"MaxDiv: Zero-Shot Machine Unlearning via Distributionally Divergent Erasing Samples","summary":"MaxDiv is a zero-shot machine unlearning method that erases knowledge from a model without access to its original training data. It generates erasing samples by negating the distributions of the data to be forgotten, and adds knowledge distillation to prevent catastrophic forgetting of retained information. Evaluations on MNIST, SVHN, CIFAR-10, CIFAR-100 and TinyImageNet reportedly show superior performance over current state-of-the-art methods.","sourceUrl":"http://ieeexplore.ieee.org/document/11222727","publishedAt":"2025-10-30T13:19:56.000Z","severity":"info","cvssSeverity":null,"cvssScore":null,"labels":["research","privacy"],"issueType":"research","cveId":null,"cweIds":null,"affectedPackages":null,"affectedVendors":[],"affectedVendorsRaw":[],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","solution":"N/A -- no mitigation discussed in source.","attackType":[],"cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"epssCheckedAt":null,"kevDateAdded":null,"advisoryAliases":null,"affectedPackagesSource":null,"patchAvailable":null,"disclosureDate":"2025-10-30T13:19:56.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":null,"aiComponentTargeted":"model","llmSpecific":false,"classifierConfidence":0.85,"researchCategory":"peer_reviewed","atlasIds":null},{"id":"477037f6-7f91-4997-b6ed-b3024f17f2db","title":"Really Unlearned? Verifying Machine Unlearning via Influential Sample Pairs","summary":"IndirectVerify is a formal scheme for verifying whether machine unlearning requests have actually been executed, addressing a gap where existing verification relies on backdoor or membership inference attacks that a model provider can bypass through rapid fine-tuning. The authors generate influential sample pairs, trigger samples and reaction samples, using a perturbation-based method that alters only a small fraction of training samples so that reaction samples are misclassified. The paper claims this indirect influence provides greater robustness against bypassing than schemes that reuse the same samples throughout.","sourceUrl":"http://ieeexplore.ieee.org/document/11202435","publishedAt":"2025-10-13T13:16:55.000Z","severity":"info","cvssSeverity":null,"cvssScore":null,"labels":["research","security"],"issueType":"research","cveId":null,"cweIds":null,"affectedPackages":null,"affectedVendors":[],"affectedVendorsRaw":[],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","solution":"N/A -- no mitigation discussed in source.","attackType":[],"cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"epssCheckedAt":null,"kevDateAdded":null,"advisoryAliases":null,"affectedPackagesSource":null,"patchAvailable":null,"disclosureDate":null,"capecIds":null,"crossRefCount":0,"attackSophistication":"advanced","impactType":["integrity"],"aiComponentTargeted":"model","llmSpecific":false,"classifierConfidence":0.9,"researchCategory":"peer_reviewed","atlasIds":null},{"id":"9af2c14e-6198-484a-bae6-8142753b1f73","title":"SMS: Self-Supervised Model Seeding for Verification of Machine Unlearning","summary":"The paper proposes Self-supervised Model Seeding (SMS), a scheme for verifying that a model has unlearned genuine user samples rather than only backdoored ones. SMS links user-specific seeds, original samples and the model through a self-supervised seeding task trained jointly with the primary service task. The authors report effectiveness across three datasets, several model architectures, and exact and approximate unlearning benchmarks.","sourceUrl":"http://ieeexplore.ieee.org/document/11184497","publishedAt":"2025-09-29T13:25:31.000Z","severity":"info","cvssSeverity":null,"cvssScore":null,"labels":["security","privacy","research"],"issueType":"research","cveId":null,"cweIds":null,"affectedPackages":null,"affectedVendors":[],"affectedVendorsRaw":[],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","solution":"N/A -- no mitigation discussed in source.","attackType":[],"cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"epssCheckedAt":null,"kevDateAdded":null,"advisoryAliases":null,"affectedPackagesSource":null,"patchAvailable":null,"disclosureDate":null,"capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":["confidentiality"],"aiComponentTargeted":"model","llmSpecific":false,"classifierConfidence":0.9,"researchCategory":"peer_reviewed","atlasIds":null},{"id":"24b9f939-b723-41de-a55c-aa7e907da1e3","title":"CVE-2024-5206: A sensitive data leakage vulnerability was identified in scikit-learn's TfidfVectorizer, specifically in versions up to…","summary":"CVE-2024-5206 affects scikit-learn's TfidfVectorizer in versions up to and including 1.4.1.post1. The vectorizer stores every token from the training data in its `stop_words_` attribute, not only the tokens TF-IDF needs, so tokens meant to be discarded, such as passwords or keys, can be exposed. The impact depends on the data the vectorizer processes.","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2024-5206","publishedAt":"2024-06-06T23:16:06.363Z","severity":"medium","cvssSeverity":"medium","cvssScore":"4.7","labels":["security","privacy"],"issueType":"vulnerability","cveId":"CVE-2024-5206","cweIds":["CWE-921","CWE-922"],"affectedPackages":["scikit-learn@< 1.5.0 (fixed: 1.5.0)"],"affectedVendors":[],"affectedVendorsRaw":["scikit-learn","TfidfVectorizer"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","solution":"Fixed in 1.5.0","attackType":["pii_leakage"],"cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":"unknown","epssScore":0.00189,"epssCheckedAt":"2026-10-10T03:00:38.586Z","kevDateAdded":null,"advisoryAliases":["GHSA-jw8x-6495-233v"],"affectedPackagesSource":"ghsa","patchAvailable":true,"disclosureDate":null,"capecIds":null,"crossRefCount":0,"attackSophistication":"trivial","impactType":["confidentiality"],"aiComponentTargeted":"framework","llmSpecific":false,"classifierConfidence":0.9,"researchCategory":null,"atlasIds":null}],"meta":{"total":17,"limit":20,"offset":0}}