Paper warns that LLM agents can recover deleted knowledge through tools
A new arXiv paper identifies a gap in LLM unlearning: an agent may stop recalling information from its weights but recover it through web search, retrieval or database tools. The authors propose a two-stage method to reduce both forms of recovery while preserving legitimate tool use.