PulseExploreJournal ClubDebatesTrendingResearchersJournals
Instagram
HomeExploreJournal ClubTrending
Synapse
⌘+K
Synapse
February 5, 2026Information0 citationsOpen Access

FedRazor: Two-Stage Federated Unlearning via Representation Divergence and Gradient Conflict Trimming

View Full Paper
YHYanxin HuXLXi LiuYHYan Huang

Key Points

  • To develop a federated unlearning framework that eliminates client influence from models while maintaining stability and accuracy.
  • Implemented a two-stage framework for federated unlearning.
  • Utilized Divergence-Smoothing Loss to reduce confidence in forgotten labels.
  • Employed Feature Mean Divergence loss to create separation from retained feature centers.
  • Introduced PCGrad Razor to trim conflicting gradient components during aggregation.
  • Conducted experiments on MNIST, CIFAR-10, and CIFAR-100 datasets with IID and non-IID settings.
  • FedRazor achieved an attack success rate (ASR) of 0.026 on CIFAR-10 Pat-50.
  • Retained accuracy of 0.659 after post-training, outperforming existing methods.
  • Consistently reduced attack success rates to near zero while maintaining model utility.

Abstract

Federated unlearning removes a client’s influence from a trained federated model without full retraining, which is required by data deletion regulations but remains difficult due to gradient coupling and recovery instability. Existing methods often rely on historical training records or suffer from severe utility degradation and model reverting after recovery. We propose FedRazor, a two-stage federated unlearning framework that achieves stable client-level unlearning through representation divergence and gradient direction control. In Stage I, FedRazor weakens dependence on forgotten data using two complementary objectives. A Divergence-Smoothing Loss reduces prediction confidence on forgotten labels, while a Feature Mean Divergence loss pushes forgotten representations away from the retained feature center. To protect retained performance, we introduce PCGrad Razor, which trims gradient components that conflict with retained gradients during aggregation. This stage produces an intermediate unlearned model without storing historical updates. In Stage II, FedRazor restores retained utility using directional gradient trimming. Gradients aligned with the unlearning displacement direction are removed, preventing forgotten information from re-entering the model during recovery. Experiments on MNIST, CIFAR-10, and CIFAR-100 under IID and non-IID settings show that FedRazor consistently reduces attack success rate to near zero while preserving retained accuracy. On CIFAR-10 Pat-50, FedRazor achieves ASR = 0.026 with retained accuracy 0.659 after post-training, outperforming strong baselines in stability and unlearning robustness.

Ask AI
Helpful
Bookmark
Share
View Full Paper

Cite This Study

Hu et al. (2026) studied this question.

synapsesocial.com/papers/698434f9f1d9ada3c1fb3cbbhttps://doi.org/10.3390/info17020146
Ask AI
Helpful
Bookmark
Share
View Full Paper