Date of Award

2026-05-01

Degree Name

Master of Science

Department

Computer Science

Advisor(s)

Aritran Piplai

Abstract

Machine unlearning aims to remove the influence of deleted data from a trained machine learning model. This is important because privacy regulations such as GDPR, CCPA, and PIPEDA give individuals the right to request the deletion of their personal data. Since unlearning can be expensive, a dishonest server may skip it or return an incorrect model and this motivates verifiable machine unlearning. Existing cryptographic approaches prove that the server executed a specific training or unlearning algorithm on the committed dataset, so the proof is tied to the algorithm's trajectory. Empirical verifiers avoid this cost but are known to be circumventable by an adversarial server. In this thesis, instead of proving the full training or unlearning path, we prove only that the returned model satisfies an optimality condition on the committed post-deletion dataset. For ridge regression and regularized logistic regression, strong convexity of the loss guarantees a unique minimizer on the retained data, so a small gradient residual at the returned model means the model is close to the unique retrained model. Combined with hashchain commitments to the dataset and the deletion history, this also closes the forgeability gap that adversarial servers could otherwise exploit, without requiring a trajectory proof. We implement this idea as a zero-knowledge proof for ridge regression and regularized binary logistic regression. We also test a restricted neural-network setting with a frozen feature extractor and a trainable logistic-regression head. Experiments on synthetic and real dataset show that the proof correctly distinguishes honest post-deletion models from dishonest ones, with proving cost that scales linearly with dataset size and feature dimension.

Language

en

Provenance

Received from ProQuest

File Size

100 p.

File Format

application/pdf

Rights Holder

Bidur Niroula

Share

COinS