Removing Information Content Does Not Certify Tamper Resistance in Open-Weight Models
arXiv:2610.09004v1 Announce Type: new Abstract: Does removing harmful information make open-weight models resistant to fine-tuning attacks? We show that mutual information at release alone cannot universally certify slow recovery. Function-preserving reparameterizations leave information unchanged…
Read the full story at arXiv cs.LG ↗
Timeline · 1 report
- 2026-10-08 04:00 · arXiv cs.LG
Removing Information Content Does Not Certify Tamper Resistance in Open-Weight Models