Modular Pretraining Enables Access Control
Ethan Roland, Murat Cubuktepe, Erick Martinez, Stijn Servaes, Keenan Pepper, Michael Vaiana, Diogo de Lucena, Judd Rosenblatt, Addie Foote, Cem Anil, Alex Cloud
Abstract
AI developers face a dual-use dilemma. An AI capability that helps one user cure a disease can help another synthesize one. This dilemma could be resolved with access control, limiting dual-use AI capabilities to trusted deployments with a legitimate need. A gold standard for access control would be to serve separate models with different capabilities to different users. However, training and deploying multiple models is prohibitively expensive. To address this challenge, we propose gradient-routed auxiliary modules (GRAM), a pretraining method that adds modules to a neural network and selectively updates them to induce specialization. Ablating a module at inference time removes its capability from the network, approximating a model trained on filtered data. We evaluate GRAM on synthetic stories and realistic dual-use data spanning virology, cybersecurity, nuclear physics, and specialized code. These experiments show that GRAM disables targeted capabilities while preserving the rest, and resists their recovery under finetuning better than posthoc unlearning. Most importantly, a Chinchillaoptimal scaling analysis from 50M to 5B parameters shows that the gap between data-filtered and full-data models widens with scale on removed capabilities but stays small on retained ones, and that GRAM closely tracks data filtering. GRAM's training cost is independent of the number of supported capability profiles, yielding a 5× reduction over data filtering in our 5-profile setting. * Equal contribution 1 AE Studio 2 Independent 3 Anthropic.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Builds on18
- Continual learning with hypernetworksJohannes von Oswald, Christian Henning, João Sacramento, Benjamin F. GreweICLR 2020 · 412 citations
- The WMDP Benchmark: Measuring and Reducing Malicious Use with UnlearningNathaniel Li, Alexander Pan, Anjali Gopal, Summer Yue et al.ICML 2024 · 390 citations
- Composing Parameter-Efficient Modules with Arithmetic OperationJinghan Zhang, Shiqi Chen, Junteng Liu, Junxian HeNeurIPS 2023 · 164 citations
- Resolving Discrepancies in Compute-Optimal Scaling of Language ModelsTomer Porian, Mitchell Wortsman, Jenia Jitsev, Ludwig Schmidt et al.NeurIPS 2024 · 94 citations
- Deep Ignorance: Filtering Pretraining Data Builds Tamper-Resistant Safeguards into Open-Weight LLMsKyle O'Brien, Stephen Casper, Quentin Anthony, Tomek Korbak et al.ICLR 2026 · 59 citations
Related papers
- No More, No Less: Least-Privilege Language ModelsPaulius Rauba, Dominykas Seputis, Patrikas Vanagas, Mihaela van der SchaarICML 2026
- Fine-grained Pluggable Gradient Ascent for Knowledge Unlearning in Language ModelsXiaohua Feng, Chaochao Chen, Yuyuan Li, Zibin LinEMNLP 2024 · 6 citations
- Trojan-Speak: Bypassing Constitutional Classifiers with No Jailbreak Tax via Adversarial FinetuningBilgehan Sel, Xuanli He, Alwin Peng, Ming Jin et al.ICML 2026
- Explainable LLM Unlearning through ReasoningJunfeng Liao, Qizhou Wang, Shanshan Ye, Xin Yu et al.ICLR 2026 · 8 citations
- Discovering Knowledge-Critical Subnetworks in Pretrained Language ModelsDeniz Bayazit, Negar Foroutan, Zeming Chen, Gail Weiss et al.EMNLP 2024 · 3 citations
