LEMUR Enhances Privacy in Multimodal LLMs by Unlearning Sensitive Reasoning.

Xinhao Zhong, Yuxia Qiao, Junhao Li, Hao Fang, Yi Sun, Bin Chen· August 13, 2026 View original

Key takeaways

  • RL-trained multimodal models can leak sensitive data in their reasoning traces.
  • Sensitive content leaves a distinct entropy signature in RL-induced exploration.
  • LEMUR is a training-free method to suppress this leakage at inference time.
  • It redirects reasoning using visual anchors, preserving utility and fluency.

Who benefits

HealthcareFinanceLegalGovernmentAI/ML Development

Summary

This research introduces LEMUR, a training-free, inference-time unlearning framework for multimodal large reasoning models (MLRMs) that addresses privacy leakage in reasoning traces. It uses entropy dynamics and visual-anchored reasoning redirection to suppress sensitive content while preserving utility.

Reinforcement learning (RL) post-training significantly improves the visual reasoning capabilities of multimodal large reasoning models (MLRMs) by enabling them to generate exploratory chains of thought (CoT). However, this enhanced reasoning introduces a new privacy vulnerability: even if a sensitive fact is removed from the final answer, it can still appear in the model's internal reasoning process. This leakage is particularly pronounced in RL-trained MLRMs compared to their base models. The researchers observed that RL-induced exploration leaves a distinct token-level entropy signature associated with sensitive content. Leveraging this insight, they developed LEMUR (Latent Entropy-aware Multimodal Unlearning via Visual-anchored Reasoning Redirection). LEMUR is a training-free, inference-time framework that uses these entropy dynamics as a control signal. When sensitive reasoning is detected, LEMUR redirects the model's reasoning trajectory. It achieves this by using entropy-modulated visual-anchor latent injection, replacing problematic tokens with sanitized, probability-weighted embeddings re-grounded in the input image. Experiments show LEMUR effectively suppresses both reasoning-trace and answer leakage across various MLRMs, outperforming existing methods while maintaining non-sensitive utility and output fluency.

Why it matters

For organizations deploying multimodal AI, LEMUR offers a critical solution for mitigating privacy risks associated with sensitive information appearing in model reasoning, ensuring compliance and user trust without costly retraining.

How to implement this in your domain

  1. 1Assess current multimodal AI deployments for potential privacy leakage in reasoning traces.
  2. 2Investigate integrating LEMUR as an inference-time privacy filter for MLRMs handling sensitive data.
  3. 3Develop internal guidelines for evaluating and mitigating privacy risks in AI-generated reasoning.
  4. 4Collaborate with research teams to adapt and extend LEMUR's principles to other AI modalities or privacy concerns.

Original post by Xinhao Zhong, Yuxia Qiao, Junhao Li, Hao Fang, Yi Sun, Bin Chen

"arXiv:2608.11691v1 Announce Type: new Abstract: Reinforcement-learning (RL) post-training equips multimodal large reasoning models (MLRMs) with exploratory chains of thought (CoT), substantially improving visual reasoning. However, we find that this capability introduces a distin…"

View on X

Originally posted by Xinhao Zhong, Yuxia Qiao, Junhao Li, Hao Fang, Yi Sun, Bin Chen on X · view source

Want to go deeper?

Turn these trends into skills with Learnijoy's hands-on AI & tech courses.

Explore courses