Changes to group membership are rolled back after the change and InTrust response actions are not suspected as the change to the group (add\remove) is rolled back on a different DC then where the original change occurred. InTrust response actions occurr on the same server where the original change took place when enabled.
Unexpected roll backs are occurring.
Group Policy may be enforcing 'Restricted Groups' which is rolling back the modification of configured groups. Check GPOs enforced which may contribute to this effect.