Could you kindly share the specific parameters when attacking with circumventing-concept-erasure? I am trying to reproduce this attack method on your and other unlearning methods, but I find the ASRs significantly lower (nearly zero) than the results reported in papers.
The issue you participated in that hub is here.
Thank you a lot in advance!