{"id":"https://openalex.org/W7133356976","doi":"https://doi.org/10.48550/arxiv.2603.01185","title":"Token-level Data Selection for Safe LLM Fine-tuning","display_name":"Token-level Data Selection for Safe LLM Fine-tuning","publication_year":2026,"publication_date":"2026-03-01","ids":{"openalex":"https://openalex.org/W7133356976","doi":"https://doi.org/10.48550/arxiv.2603.01185"},"language":null,"primary_location":{"id":"doi:10.48550/arxiv.2603.01185","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2603.01185","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":null,"is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"article"},"type":"preprint","indexed_in":["datacite"],"open_access":{"is_oa":true,"oa_status":"green","oa_url":"https://doi.org/10.48550/arxiv.2603.01185","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5127981649","display_name":"Yanping Li","orcid":null},"institutions":[],"countries":[],"is_corresponding":true,"raw_author_name":"Li, Yanping","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5065711649","display_name":"Zhening Liu","orcid":"https://orcid.org/0000-0002-6512-152X"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Liu, Zhening","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5127895613","display_name":"Zijian Li","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Li, Zijian","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5063294279","display_name":"Zehong Lin","orcid":"https://orcid.org/0000-0002-9503-2464"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Lin, Zehong","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"last","author":{"id":"https://openalex.org/A5127961334","display_name":"Jun Zhang (48506)","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Zhang, Jun","raw_affiliation_strings":[],"affiliations":[]}],"institutions":[],"countries_distinct_count":0,"institutions_distinct_count":5,"corresponding_author_ids":["https://openalex.org/A5127981649"],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":null,"has_fulltext":false,"cited_by_count":0,"citation_normalized_percentile":null,"cited_by_percentile_year":null,"biblio":{"volume":null,"issue":null,"first_page":null,"last_page":null},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.7368999719619751,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.7368999719619751,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10028","display_name":"Topic Modeling","score":0.05079999938607216,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.030300000682473183,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/task","display_name":"Task (project management)","score":0.5864999890327454},{"id":"https://openalex.org/keywords/identification","display_name":"Identification (biology)","score":0.574999988079071},{"id":"https://openalex.org/keywords/selection","display_name":"Selection (genetic algorithm)","score":0.5472999811172485},{"id":"https://openalex.org/keywords/granularity","display_name":"Granularity","score":0.4848000109195709},{"id":"https://openalex.org/keywords/code","display_name":"Code (set theory)","score":0.4016000032424927},{"id":"https://openalex.org/keywords/security-token","display_name":"Security token","score":0.32350000739097595}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7401000261306763},{"id":"https://openalex.org/C2780451532","wikidata":"https://www.wikidata.org/wiki/Q759676","display_name":"Task (project management)","level":2,"score":0.5864999890327454},{"id":"https://openalex.org/C116834253","wikidata":"https://www.wikidata.org/wiki/Q2039217","display_name":"Identification (biology)","level":2,"score":0.574999988079071},{"id":"https://openalex.org/C81917197","wikidata":"https://www.wikidata.org/wiki/Q628760","display_name":"Selection (genetic algorithm)","level":2,"score":0.5472999811172485},{"id":"https://openalex.org/C177774035","wikidata":"https://www.wikidata.org/wiki/Q1246948","display_name":"Granularity","level":2,"score":0.4848000109195709},{"id":"https://openalex.org/C124101348","wikidata":"https://www.wikidata.org/wiki/Q172491","display_name":"Data mining","level":1,"score":0.46810001134872437},{"id":"https://openalex.org/C2776760102","wikidata":"https://www.wikidata.org/wiki/Q5139990","display_name":"Code (set theory)","level":3,"score":0.4016000032424927},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.36820000410079956},{"id":"https://openalex.org/C112930515","wikidata":"https://www.wikidata.org/wiki/Q4389547","display_name":"Risk analysis (engineering)","level":1,"score":0.3582000136375427},{"id":"https://openalex.org/C48145219","wikidata":"https://www.wikidata.org/wiki/Q1335365","display_name":"Security token","level":2,"score":0.32350000739097595},{"id":"https://openalex.org/C93959086","wikidata":"https://www.wikidata.org/wiki/Q6888345","display_name":"Model selection","level":2,"score":0.3050999939441681},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.29159998893737793},{"id":"https://openalex.org/C67186912","wikidata":"https://www.wikidata.org/wiki/Q367664","display_name":"Data modeling","level":2,"score":0.2728999853134155},{"id":"https://openalex.org/C200601418","wikidata":"https://www.wikidata.org/wiki/Q2193887","display_name":"Reliability engineering","level":1,"score":0.2718999981880188},{"id":"https://openalex.org/C193519340","wikidata":"https://www.wikidata.org/wiki/Q891179","display_name":"Data loss","level":2,"score":0.26809999346733093},{"id":"https://openalex.org/C26517878","wikidata":"https://www.wikidata.org/wiki/Q228039","display_name":"Key (lock)","level":2,"score":0.26339998841285706}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.48550/arxiv.2603.01185","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2603.01185","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":null,"is_accepted":false,"is_published":null,"raw_source_name":null,"raw_type":"article"}],"best_oa_location":{"id":"doi:10.48550/arxiv.2603.01185","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2603.01185","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":null,"is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"article"},"sustainable_development_goals":[{"id":"https://metadata.un.org/sdg/16","score":0.45117247104644775,"display_name":"Peace, Justice and strong institutions"}],"awards":[],"funders":[],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":0,"referenced_works":[],"related_works":[],"abstract_inverted_index":{"Fine-tuning":[0],"large":[1],"language":[2],"models":[3,16],"(LLMs)":[4],"on":[5,74],"custom":[6],"datasets":[7],"has":[8],"become":[9],"a":[10,64,86,103,107,130],"standard":[11],"approach":[12,151],"for":[13,81],"adapting":[14],"these":[15],"to":[17,32,142],"specific":[18],"domains":[19],"and":[20,47,56,106,116],"applications.":[21],"However,":[22],"recent":[23],"studies":[24],"have":[25],"shown":[26],"that":[27,89,149],"such":[28],"fine-tuning":[29,84,156],"can":[30],"lead":[31],"significant":[33],"degradation":[34,70],"in":[35],"the":[36,44,91,99,138],"model's":[37,140],"safety.":[38],"Existing":[39],"defense":[40,167],"methods":[41],"operate":[42],"at":[43,173],"sample":[45],"level":[46],"often":[48],"suffer":[49],"from":[50],"an":[51],"unsatisfactory":[52],"trade-off":[53],"between":[54,102],"safety":[55,69,92],"utility.":[57],"To":[58],"address":[59],"this":[60],"limitation,":[61],"we":[62,76,128],"perform":[63],"systematic":[65],"token-level":[66,78,111],"diagnosis":[67],"of":[68,94,118],"during":[71,155],"fine-tuning.":[72],"Based":[73],"this,":[75],"propose":[77],"data":[79],"selection":[80],"safe":[82],"LLM":[83],"(TOSS),":[85],"novel":[87],"framework":[88],"quantifies":[90],"risk":[93],"each":[95],"token":[96],"by":[97],"measuring":[98],"loss":[100],"difference":[101],"safety-degraded":[104,139],"model":[105],"utility-oriented":[108],"model.":[109],"This":[110],"granularity":[112],"enables":[113],"accurate":[114],"identification":[115],"removal":[117],"unsafe":[119,144],"tokens,":[120],"thereby":[121],"preserving":[122],"valuable":[123],"task-specific":[124],"information.":[125],"In":[126],"addition,":[127],"introduce":[129],"progressive":[131],"refinement":[132],"strategy,":[133],"TOSS-Pro,":[134],"which":[135],"iteratively":[136],"enhances":[137],"ability":[141],"identify":[143],"tokens.":[145],"Extensive":[146],"experiments":[147],"demonstrate":[148],"our":[150],"robustly":[152],"safeguards":[153],"LLMs":[154],"while":[157],"achieving":[158],"superior":[159],"downstream":[160],"task":[161],"performance,":[162],"significantly":[163],"outperforming":[164],"existing":[165],"sample-level":[166],"methods.":[168],"Our":[169],"code":[170],"is":[171],"available":[172],"https://github.com/Polly-LYP/TOSS.":[174]},"counts_by_year":[],"updated_date":"2026-03-04T07:09:34.246503","created_date":"2026-03-04T00:00:00"}
