[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"branding":3,"analytics":7,"article-ai-models-still-know-what-they-were-told-to-forget":10,"sections":49},{"siteName":4,"siteTagline":5,"publisherName":4,"contactEmail":6},"The Revision","Tech news, decoded.","editor@therevision.news",{"gaMeasurementId":8,"adsenseClientId":9},"G-ZW2MV82GYR","ca-pub-8533917693782264",{"article":11},{"id":12,"slug":13,"title":14,"dek":15,"body_md":16,"tags_json":17,"published_at":18,"created_at":19,"updated_at":20,"status":21,"review_note":22,"review_notes":23,"image_url":22,"persona_id":22,"persona_name":22,"section":39,"tags":40,"sources":44,"feedback":48,"feedback_at":22,"cost_usd":48,"total_tokens":48},8707,"ai-models-still-know-what-they-were-told-to-forget","AI Models Still Know What They Were Told to Forget","A new study finds that telling a vision-language model to suppress a concept just changes its wording, not what it can still recognize.","Asking an AI model to forget a concept doesn't make it forget - it just makes it cagier.\n\nA paper posted to arXiv this week, \"Suppression Is Not Forgetting: Residual Recoverability in Visual Concept Unlearning for VLMs\" (arXiv:2604.03114v2, updated September 2026 despite the April submission stamp baked into its ID), tested what happens when off-the-shelf vision-language models are told to stop naming things they can see. The researchers first confirmed each model could actually recognize a given object, scene, or person from an image, then probed it three ways: multiple-choice, short-answer, and indirect questions. Prompt-based suppression, the cheap, training-free method available to anyone stuck with an API-only model, cut short-answer recall for some concepts. Multiple-choice and indirect recall barely moved, and spelling out the exact list of concepts to suppress sometimes made a model more likely to name one, not less.\n\nThat gap matters for anyone treating a system prompt as a compliance fix. If a company can't retrain or fine-tune a model because it doesn't own the weights, telling it \"don't identify this person\" looks like unlearning. The paper's point is that the concept is still in there and still retrievable, just no longer volunteered under one specific phrasing.\n\nThe same caveat held for decoding constraints, representation editing, and even parameter updates in the study, so this isn't purely a prompting problem - it's a reminder that a model going quiet about something is not the same as a model that has forgotten it.","[\"ai\",\"vision-language-models\",\"machine-unlearning\",\"ai-safety\"]","2026-09-30T04:00:00.000Z","2026-09-30T20:42:35.251Z","2026-09-30T20:42:41.341Z","published",null,[24,30,35],{"id":25,"reviewer":26,"round":27,"reason":28,"status":29},"editor-r1","editor",1,"Add explicit attribution (arXiv paper title\u002FID and date) for the study instead of just 'researchers,' and briefly explain what the short-answer\u002Fmultiple-choice recall metrics measure so readers can judge the unquantified performance claims.","resolved",{"id":31,"reviewer":32,"round":33,"reason":34,"status":29},"publisher-r2","publisher",2,"The arXiv ID 2604.03114 encodes a April 2026 (YYMM=2604) submission, which contradicts the stated posting date of September 30, 2026.",{"id":36,"reviewer":26,"round":37,"reason":38,"status":29},"editor-r3",3,"Add explicit source attribution (e.g., name the arXiv preprint and its actual posting date) for the findings, since the draft currently presents them with no named source at all — and ensure any date\u002FID cited matches the real September 2026 posting rather than the April 2026 (2604) submission stamp.","ai",[39,41,42,43],"vision-language-models","machine-unlearning","ai-safety",[45],{"name":46,"url":47},"arXiv cs.AI","https:\u002F\u002Farxiv.org\u002Fabs\u002F2604.03114",0,{"sections":50},[51,54,58,62,67,72,76,81,86,90,95,100,105,110],{"name":52,"slug":39,"count":53,"latest_published_at":18},"AI",5184,{"name":55,"slug":56,"count":57,"latest_published_at":18},"Security","security",791,{"name":59,"slug":60,"count":61,"latest_published_at":18},"Policy","policy",417,{"name":63,"slug":64,"count":65,"latest_published_at":66},"Deals","deals",284,"2026-09-29T21:00:00.000Z",{"name":68,"slug":69,"count":70,"latest_published_at":71},"Hardware","hardware",194,"2026-09-29T13:16:04.000Z",{"name":73,"slug":74,"count":75,"latest_published_at":18},"Science","science",155,{"name":77,"slug":78,"count":79,"latest_published_at":80},"Consumer Tech","consumer-tech",142,"2026-09-29T18:38:03.000Z",{"name":82,"slug":83,"count":84,"latest_published_at":85},"Software","software",91,"2026-09-25T20:55:00.000Z",{"name":87,"slug":88,"count":89,"latest_published_at":18},"Dev Tools","dev-tools",90,{"name":91,"slug":92,"count":93,"latest_published_at":94},"Startups","startups",83,"2026-09-29T21:51:36.000Z",{"name":96,"slug":97,"count":98,"latest_published_at":99},"General","general",49,"2026-09-28T16:44:57.000Z",{"name":101,"slug":102,"count":103,"latest_published_at":104},"Gaming","gaming",48,"2026-09-25T18:35:21.000Z",{"name":106,"slug":107,"count":108,"latest_published_at":109},"Reviews","reviews",31,"2026-09-28T14:31:34.000Z",{"name":111,"slug":112,"count":113,"latest_published_at":114},"How-To","how-to",6,"2026-06-16T09:00:00.000Z"]