[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-85050-en":3,"doc-seo-85050-105":29,"detail-sidebar-cat-0-en-105":91},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":20,"is_downloadable":20,"audit_status":20,"page_count":21,"language":22,"language_code":23,"site_id":24,"html_lang":23,"table_of_contents":25,"faqs":26,"seo_title":13,"seo_description":14,"update_tm":27,"read_time":28},85050,1099514067415,"Rowan","https://ap-avatar.wpscdn.com/avatar/100002539d78ffe74a7?x-image-process=image/resize,m_fixed,w_180,h_180&k=1779092875211072502",8,"Research & Report","Modular Pretraining Enables Access Control","AI developers face a dual-use dilemma: useful capabilities in one setting can enable harm in another. Access control—serving capabilities only to trusted users with legitimate needs—could mitigate misuse, but training multiple specialized models is prohibitively expensive. Gradient-routed auxiliary modules (GRAM) address this by adding selectively updated modules during pretraining, so ablating modules removes capabilities. Evaluations across synthetic stories and realistic dual-use data show strong capability disabling, better resistance to recovery under finetuning than posthoc unlearning, and favorable scaling and cost tradeoffs.","Modular Pretraining Enables Access Control  \nEthan Roland * 1 Murat Cubuktepe * 1 Erick Martinez * 1 Stijn Servaes 1 Keenan Pepper 1 Mike Vaiana 1 Diogo Schwerz de Lucena 1 Judd Rosenblatt 1 Addie Foote 2 Cem Anil 3 Alex Cloud 3  \narXiv :2607 .08077v 1 [ cs .LG] 9 Jul 2026  \nAbstract  \nAI developers face a dual-use dilemma. An AI capability that helps one user cure a disease can help another synthesize one. This dilemma could be resolved with access control, limiting dual-use AI capabilities to trusted deployments with a legitimate need. A gold standard for access control would be to serve separate models with different capabilities to different users. However, training and deploying multiple models is prohibitively expensive. To address this challenge, we propose gradient-routed auxiliary modules (GRAM), a pretraining method that adds modules to a neural network and selectively updates them to induce specialization. Ablating a module at inference time removes its capability from the network, approximating a model trained on filtered data. We evaluate GRAM on synthetic stories and realistic dual-use data spanning virology, cybersecurity, nuclear physics, and specialized code. These experiments show that GRAM disables targeted capabilities while preserving the rest, and resists their recovery under finetuning better than posthoc unlearning. Most importantly, a Chinchillaoptimal scaling analysis from 50M to 5B parameters shows that the gap between data-filtered and full-data models widens with scale on removed capabilities but stays small on retained ones, and that GRAM closely tracks data filtering. GRAM’straining cost is independent of the number of supported capability profiles, yielding a 5 × reduction over data filtering in our 5-profile setting.  \n1. Introduction  \nSome AI capabilities are dual-use, enabling both beneficial and harmful applications (Brundage et al., 2018) . For example, the knowledge required to manufacture vaccines overlaps with that needed to develop biological weapons (Sand-  \n*Equal contribution 1AE Studio 2Independent 3Anthropic. Correspondence to: Ethan Roland \u003C[ethan@ae.studio](ethan@ae.studio) >.  \nbrink & Koblentz, 2022 ; Drew & Mueller-Doblies, 2017); similarly, knowledge of cybersecurity can be used to fortify computer systems or to execute attacks against them (Truong et al., 2020 ; Roguski, 2021) . Models deployed with dual-use capabilities pose misuse risk, yet withholding these models forfeits their benefits. Without mechanisms for differentiated access, AI developers face an all-or-nothing choice: the dual-use dilemma (Miller & Selgelid, 2007) .  \nAccess control, the restriction of access to resources based on user authorization, could help address this dilemma (Sandhu & Samarati, 1994 ; Wybitul, 2025) . Rather than exposing every capability in every deployment, AI developers could provide model variants appropriate to specific deployments based on trust and need. This is consistent with established security principles such as least privilege (Saltzer & Schroeder, 1975 ; NIST, 2020), which holds that permissions should be restricted only to those required to perform a task.  \nFor LLMs, we define a capability informally as the ability to perform a particular type of task, and define a capability profile as a collection of capabilities. A gold standard for AI access control would be to serve separately trained models with different capability profiles to different users. This standard could be achieved by data filtering across multiple training runs, each removing a different subset of the corpus to induce a specific profile. Because each resulting model never saw the filtered data, it is robust to adversarial elicitation such as finetuning (Maini et al., 2025 ; O’Brien et al., 2025) . However, supporting N capability profiles requires training and deploying N separate models, which is prohibitively costly at frontier scale (Cottier et al., 2024) .  \nThis cost has motivated cheaper approximat","cbCailjdxZEmGejC","https://ap.wps.com/l/cbCailjdxZEmGejC","pdf",1095168,1,34,"English","en",105,"# Abstract\n# Introduction\n## Dual-use dilemma and access control\n## Capability profiles and gold-standard approaches\n## Limitations of existing removal and unlearning methods\n## Proposed GRAM method\n## Evaluation setup and results","[{\"question\":\"What dual-use problem does the document address?\",\"answer\":\"It addresses the dilemma that AI capabilities useful for beneficial tasks can also be used to synthesize harmful ones, creating misuse risk when models are deployed without differentiated access.\"},{\"question\":\"How does GRAM achieve capability-specific access control without training many models?\",\"answer\":\"GRAM adds auxiliary modules during pretraining and selectively routes forward/backward updates so different modules specialize to different capabilities, enabling removal by ablating modules at inference.\"},{\"question\":\"What experiments and domains are used to evaluate GRAM?\",\"answer\":\"The evaluation uses synthetic stories and realistic dual-use data spanning virology, cybersecurity, nuclear physics, and specialized code.\"}]",1784200643,86,{"code":4,"msg":30,"data":31},"ok",{"site_id":24,"language":23,"slug":32,"title":13,"keywords":33,"description":14,"schema_data":34,"social_meta":86,"head_meta":88,"extra_data":90,"updated_unix":27},"modular-pretraining-enables-access-control","",{"@graph":35,"@context":85},[36,53,68],{"@type":37,"itemListElement":38},"BreadcrumbList",[39,43,47,50],{"item":40,"name":41,"@type":42,"position":20},"https://docshare.wps.com","Home","ListItem",{"item":44,"name":45,"@type":42,"position":46},"https://docshare.wps.com/document/","Document",2,{"item":48,"name":12,"@type":42,"position":49},"https://docshare.wps.com/document/research-report/",3,{"item":51,"name":13,"@type":42,"position":52},"https://docshare.wps.com/document/modular-pretraining-enables-access-control/85050/",4,{"url":51,"name":13,"@type":54,"author":55,"headline":13,"publisher":57,"fileFormat":60,"inLanguage":23,"description":14,"dateModified":61,"datePublished":62,"encodingFormat":60,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":56},"Person",{"url":40,"name":58,"@type":59},"DocShare","Organization","application/pdf","2026-07-17","2026-07-16",true,{"@type":65,"interactionType":66,"userInteractionCount":20},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81],{"name":72,"@type":73,"acceptedAnswer":74},"What dual-use problem does the document address?","Question",{"text":75,"@type":76},"It addresses the dilemma that AI capabilities useful for beneficial tasks can also be used to synthesize harmful ones, creating misuse risk when models are deployed without differentiated access.","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"How does GRAM achieve capability-specific access control without training many models?",{"text":80,"@type":76},"GRAM adds auxiliary modules during pretraining and selectively routes forward/backward updates so different modules specialize to different capabilities, enabling removal by ablating modules at inference.",{"name":82,"@type":73,"acceptedAnswer":83},"What experiments and domains are used to evaluate GRAM?",{"text":84,"@type":76},"The evaluation uses synthetic stories and realistic dual-use data spanning virology, cybersecurity, nuclear physics, and specialized code.","https://schema.org",{"og:url":51,"og:type":87,"og:title":13,"og:site_name":58,"og:description":14},"article",{"robots":89,"canonical":51},"index,follow",{"doc_id":7,"site_id":24},{"code":4,"msg":5,"data":92},[93,97,101,105,110,115,120,123,128,131,135],{"id":20,"doc_module":4,"doc_module_name":45,"category_name":94,"show_sort_weight":95,"slug":96},"Story & Novel",90,"story-novel",{"id":46,"doc_module":4,"doc_module_name":45,"category_name":98,"show_sort_weight":99,"slug":100},"Literature",80,"literature",{"id":52,"doc_module":4,"doc_module_name":45,"category_name":102,"show_sort_weight":103,"slug":104},"Exam",70,"exam",{"id":106,"doc_module":4,"doc_module_name":45,"category_name":107,"show_sort_weight":108,"slug":109},5,"Comic",60,"comic",{"id":111,"doc_module":4,"doc_module_name":45,"category_name":112,"show_sort_weight":113,"slug":114},6,"Technology",50,"technology",{"id":116,"doc_module":4,"doc_module_name":45,"category_name":117,"show_sort_weight":118,"slug":119},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":45,"category_name":12,"show_sort_weight":121,"slug":122},30,"research-report",{"id":124,"doc_module":4,"doc_module_name":45,"category_name":125,"show_sort_weight":126,"slug":127},9,"Religion & Spirituality",20,"religion-spirituality",{"id":126,"doc_module":4,"doc_module_name":45,"category_name":129,"show_sort_weight":126,"slug":130},"World Cup","world-cup",{"id":132,"doc_module":4,"doc_module_name":45,"category_name":133,"show_sort_weight":132,"slug":134},10,"Lifestyle","lifestyle",{"id":136,"doc_module":4,"doc_module_name":45,"category_name":137,"show_sort_weight":106,"slug":138},19,"General","general"]