[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"branding":3,"analytics":7,"article-researchers-find-a-way-to-prove-ai-skill-edits-actually-work":10,"sections":35},{"siteName":4,"siteTagline":5,"publisherName":4,"contactEmail":6},"The Revision","Tech news, decoded.","editor@therevision.news",{"gaMeasurementId":8,"adsenseClientId":9},"G-ZW2MV82GYR","ca-pub-8533917693782264",{"article":11},{"id":12,"slug":13,"title":14,"dek":15,"body_md":16,"tags_json":17,"published_at":18,"created_at":19,"updated_at":20,"status":21,"review_note":22,"review_notes":23,"image_url":22,"persona_id":22,"persona_name":22,"section":24,"tags":25,"sources":30,"feedback":34,"feedback_at":22,"cost_usd":34,"total_tokens":34},10060,"researchers-find-a-way-to-prove-ai-skill-edits-actually-work","Researchers Find a Way to Prove AI Skill Edits Actually Work","A new proof method shows most tests for erasing an AI skill can be fooled, and offers a way to mathematically guarantee the skill is really gone.","A new paper proves that the usual way we check whether an AI unlearning edit worked, testing a bunch of examples, can never actually prove the skill is gone.\n\nThe method targets mechanistic edits: the ablations, weight tweaks, and activation steering researchers use to strip a harmful capability out of a model while keeping its useful skills intact. Instead of testing a sample of inputs, the authors use sound bound propagation to certify that an edit removes one skill and preserves another across an entire continuous region of a model's embedding space. They demonstrate the approach on networks ranging from toy ReLU models up to a standard transformer with softmax and LayerNorm, and the switch to bound propagation lets them cover roughly nine times the input-perturbation dimension an exact solver could handle.\n\nThat distinction matters because testing alone cannot rule out failure. The authors prove that no finite deterministic black-box test can certify a skill is truly removed: an edit can pass every test thrown at it and still fail on a survivor pocket of inputs that can be shrunk arbitrarily small and still exist. For anyone relying on unlearning to strip dangerous capabilities out of a model, that is the gap between we checked and we proved.\n\nThe guarantees so far only run on small, standard-architecture networks, and they require the target skill to have a decidable specification, a bar most real-world harms do not clear.","[\"ai safety\",\"mechanistic interpretability\",\"formal verification\",\"machine unlearning\"]","2026-10-05T04:00:00.000Z","2026-10-05T20:58:16.504Z","2026-10-05T20:58:21.594Z","published",null,[],"ai",[26,27,28,29],"ai safety","mechanistic interpretability","formal verification","machine unlearning",[31],{"name":32,"url":33},"arXiv cs.AI","https:\u002F\u002Farxiv.org\u002Fabs\u002F2610.03502",0,{"sections":36},[37,40,44,49,54,59,63,68,72,77,82,87,92,97],{"name":38,"slug":24,"count":39,"latest_published_at":18},"AI",6290,{"name":41,"slug":42,"count":43,"latest_published_at":18},"Security","security",869,{"name":45,"slug":46,"count":47,"latest_published_at":48},"Policy","policy",444,"2026-10-03T15:02:01.000Z",{"name":50,"slug":51,"count":52,"latest_published_at":53},"Deals","deals",323,"2026-10-04T13:00:00.000Z",{"name":55,"slug":56,"count":57,"latest_published_at":58},"Hardware","hardware",204,"2026-10-03T14:50:50.000Z",{"name":60,"slug":61,"count":62,"latest_published_at":18},"Science","science",178,{"name":64,"slug":65,"count":66,"latest_published_at":67},"Consumer Tech","consumer-tech",158,"2026-10-03T03:21:12.000Z",{"name":69,"slug":70,"count":71,"latest_published_at":18},"Dev Tools","dev-tools",98,{"name":73,"slug":74,"count":75,"latest_published_at":76},"Software","software",97,"2026-10-04T10:00:00.000Z",{"name":78,"slug":79,"count":80,"latest_published_at":81},"Startups","startups",92,"2026-10-04T14:36:25.000Z",{"name":83,"slug":84,"count":85,"latest_published_at":86},"Gaming","gaming",53,"2026-10-02T02:50:39.000Z",{"name":88,"slug":89,"count":90,"latest_published_at":91},"General","general",51,"2026-10-05T02:35:01.000Z",{"name":93,"slug":94,"count":95,"latest_published_at":96},"Reviews","reviews",32,"2026-10-02T18:00:00.000Z",{"name":98,"slug":99,"count":100,"latest_published_at":101},"How-To","how-to",7,"2026-10-01T09:00:00.000Z"]