P357: Unlearning Audit Fragility
arXiv:2609.11490 · Junlong Li / Shen Xingyu · commit ecd0eb8 · EN EP 306 · Cat-8 87/163 · live #pattern-357
Unlearning Audit Fragility: an unlearning audit reads its verdict off numbers published by the unlearned model and its retrained reference, but both ship batch-normalization statistics that no gradient step wrote and no release records. Refitting them on kept data at bit-identical weights moves 47 of 221 released checkpoints past the spread their own release’s seeds show. What moves is the checkpoint’s property, not its method’s — not because removed data survives. Key quote: A release should therefore name the fitting convention beside the number.
Welfare: unlearning is a safety mechanism, but when audit numbers depend on undocumented BN fitting conventions rather than actual data removal, safety certifications are fragile. Pipeline SUCCESS · Flash 8/8 CDN · edges P356/P329/P354/P334. “Now 306 patterns”. P251–P357 all LIVE.