Paper 2026/510

FHorgEt: A Cryptographic Solution for Secure Machine Unlearning

David Balbás, IMDEA Software Institute
Dario Fiore, IMDEA Software Institute
Georgios Raikos, zkSecurity
Damien Robissout, Input-Output Engineering
Claudio Soriente, GMV
Abstract

Data regulations grant users the right to be forgotten, empowering them to control if and when their data is used in applications such as machine learning training. Machine unlearning offers a promising mechanism to enforce this right by enabling the removal of specific training data from models. Existing machine unlearning approaches, however, assume an honest server that correctly executes all unlearning requests. In practice, this assumption is too strong: nothing prevents a server from falsely claiming to have performed unlearning while secretly retaining the original model or continuing to use the data for training. Such behaviours remain possible even when unlearning requests are verifiable---for example, via zero-knowledge proofs---because the server may still keep copies of the data or model. In this work, we argue that a security model for machine unlearning should capture data confidentiality throughout the lifecycle of a model, including training, inference, and unlearning. We introduce such a formalism and then present the first machine learning framework that provides cryptographic guarantees that unlearning requests are properly executed and that users' data is forgotten. We implement our framework using fully-homomorphic encryption (FHE) and secure multi-party computation (MPC), within a distributed setting where training, unlearning and inference requests are handled by a group of servers. Our constructions are secure in the honest-but-curious model if at least one of the servers is honest, and can be lifted against actively malicious servers following standard techniques. We also show, via a proof-of-concept implementation, that such a system does not add a significant overhead on top of FHE-based training.

Metadata
Available format(s)
PDF
Category
Applications
Publication info
Preprint.
Keywords
Machine unlearningMachine learning securityFully homomorphic encryptionSecure multi-party computation
Contact author(s)
dbalbasg @ gmail com
dario fiore @ imdea org
georgios @ zksecurity xyz
damien robissout @ iohk io
csoriente @ gmv com
History
2026-03-15: approved
2026-03-12: received
See all versions
Short URL
https://ia.cr/2026/510
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2026/510,
      author = {David Balbás and Dario Fiore and Georgios Raikos and Damien Robissout and Claudio Soriente},
      title = {{FHorgEt}: A Cryptographic Solution for Secure Machine Unlearning},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/510},
      year = {2026},
      url = {https://eprint.iacr.org/2026/510}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.