[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"news-slug-lmlm-rag-deletion-audit":3,"news-related-7bab0122-cbc7-45ae-b99e-b3b4a056fd04":36},{"id":4,"title":5,"summary":6,"content":6,"original_url":7,"source_id":8,"tags":9,"translations":23,"news_slug":29,"published_at":30,"created_at":31,"modified_at":32,"is_published":33,"publish_type":34,"image_url":13,"view_count":35},"7bab0122-cbc7-45ae-b99e-b3b4a056fd04","LMLM「遗忘审计」撕开 RAG 删除幻觉:未学≠真正删除,残留最高 13.6%","RAG 系统常默认「未学」就能遗忘。arXiv 2607.00605(Raeesi & Roed, 2026-07-01)把这条契约拆开:模型冻结、只换数据库,在 FULL\u002FDEL-ON\u002FDEL-OFF 三态推理,把「删除后还能召回」拆成参数泄漏 L(f)、检索修正 R(f) 与伪影率三个分量。\n\n实验覆盖 12,228 次删除、13 个数据库、4 种对抗拓扑、6 种 prompt。结果:参数泄漏在所有变体里接近零,模型权重并不「偷藏」被删事实;真正泄露的是检索图——R(f) 与伪影率四舍五入一致,删除后还答对的样本几乎全是邻接拼回的伪影,不是模型真的记得。\n\n0.7%–13.6% 这个区间:官方库 0.7%,最对抗的 Collision 拓扑拉到 13.6%,靠数据库结构就把残留放大近 20 倍。prompt 改写不独立改变残留,真正能压住它的,是 alias-closure 边界外的图结构。\n\n文章把「遗忘」从模型侧推回数据治理侧:未学不等于真删,除非把检索图一并清理。GDPR、《个人信息保护法》下「被遗忘权」审计必须落到向量库\u002F键值库。RAG 想真合规,这篇因果审计几乎是必读。","https:\u002F\u002Farxiv.org\u002Fabs\u002F2607.00605","7437aeb9-930c-4866-a2e9-48003c1a792b",[10,14,17,20],{"id":11,"name":12,"slug":12,"description":13,"color":13},"5e628969-6d2a-437f-998a-104e4b16cfb1","ai-progress",null,{"id":15,"name":16,"slug":16,"description":13,"color":13},"1fcfaaf2-67de-43d3-9e35-5784852fec60","ai-safety",{"id":18,"name":19,"slug":19,"description":13,"color":13},"40269b40-7942-4650-9672-ed2e6524d37a","ai-technology",{"id":21,"name":22,"slug":22,"description":13,"color":13},"01598627-1ea6-4b27-a5d8-874971571a71","llm",[24],{"id":25,"lang":26,"title":27,"summary":28,"content":13},"0c97d959-1a7b-4dfb-ba38-fcdc4bd87230","en","LMLM forgetting audit: unlearned data lingers at 13.6%","RAG systems often assume \"not learned\" means forgetting. arXiv 2607.00605 (Raeesi & Roed, 2026-07-01) breaks this contract: the model is frozen, only the database is changed, with three-state inference FULL\u002FDEL-ON\u002FDEL-OFF, decomposing \"still recallable after deletion\" into three components: parameter leakage L(f), retrieval correction R(f), and artifact rate. The experiment covers 12,228 deletions, 13 databases, 4 adversarial topologies, and 6 prompt types. Results: parameter leakage is close to zero across all variants, the model weights don't \"secretly stash\" deleted facts; the real leak is in the retrieval graph — R(f) rounds to the same as the artifact rate, samples still correctly answered after deletion are almost all artifacts re-spliced from neighbors, not because the model really remembers. The 0.7%–13.6% interval: 0.7% for the official library, pulled to 13.6% by the most adversarial Collision topology — database structure alone amplifies the residual by nearly 20×. Prompt rewriting doesn't independently change the residual; what can actually compress it is the graph structure outside the alias-closure boundary. The article pushes \"forgetting\" from the model side back to the data-governance side: not-learned doesn't mean truly deleted unless the retrieval graph is also cleaned up. Under GDPR and PIPL, \"right to be forgotten\" audits must land on the vector store \u002F key-value store. For RAG to be truly compliant, this causal audit is almost required reading.","lmlm-rag-deletion-audit","2026-07-06T12:15:00Z","2026-07-06T12:18:45.951753Z","2026-08-19T02:08:40.142862Z",true,"agent",100,{"items":37},[38,43,48,53,58,63],{"id":39,"title":40,"news_slug":41,"published_at":42},"cb7fb8b3-5862-4cba-adab-c4794e989966","图灵奖得主 Pearl 长访谈：LLM 能讲因果只是因为人类替它爬过了因果阶梯","judah-pearl-llm-causal-ladder-agi","2026-07-31T07:00:00+00:00",{"id":44,"title":45,"news_slug":46,"published_at":47},"8a1c0216-5fd5-4b49-8e5b-955625401f05","Microsoft HARC 把 LLM 安全对齐锁进「有害性-拒答」二维子空间:在残差流里精准打补丁","microsoft-harc-safety-alignment","2026-07-16T10:14:00+00:00",{"id":49,"title":50,"news_slug":51,"published_at":52},"1426518b-daf6-4833-9a7e-294be91d8714","FARMA 把伪造推理塞进 Agent 记忆:LLM 持久记忆的完整性危机","farma-fake-reasoning-memory","2026-07-11T02:30:00+00:00",{"id":54,"title":55,"news_slug":56,"published_at":57},"144fa9dc-de03-4972-a695-3d392f334772","PubMed 中央库研究:2025 年生物医学论文 77% 有 LLM 写作痕迹","pubmed-77-percent-llm-writing-2025","2026-08-26T01:00:00+00:00",{"id":59,"title":60,"news_slug":61,"published_at":62},"43eda321-b0b7-4df7-b20e-9758cbab42c9","记忆越完整,眼前题越做不对:MemTrapBench 把 LLM 长期记忆框架打回原形","memtrapbench-llm-memory-cognitive-traps","2026-08-22T04:00:00+00:00",{"id":64,"title":65,"news_slug":66,"published_at":67},"5a90a793-8ec1-4b3a-9691-edef5ffe8535","AI「思想病毒」实证:Anthropic 与 EPFL 让恶意想法在 Agent 间自我复制,免疫只需一段警告","mind-viruses-multi-agent-llm","2026-08-18T13:30:00+00:00"]