{"about":{"site":"https://codewithpapers.app","non_affiliation":"Code with Papers and Syntology are not affiliated with, endorsed by, or sponsored by Papers with Code, Meta, or the pwc-archive mirror.","licence":"CC BY-SA 4.0","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","attribution":"https://codewithpapers.app/attribution","modified":"archive material modified by Syntology; see the attribution page"},"url":"/paper/arxiv-2601-03401","title":"Rendering Data Unlearnable by Exploiting LLM Alignment Mechanisms","arxiv_id":"2601.03401","date":"2026-01-06","proceeding":null,"authors":["Ruihan Zhang","Jun Sun"],"abstract":"Large language models (LLMs) are increasingly trained on massive, heterogeneous text corpora, raising serious concerns about the unauthorised use of proprietary or personal data during model training. In this work, we address the problem of data protection against unwanted model learning in a realistic black-box setting. We propose Disclaimer Injection, a novel data-level defence that renders text unlearnable to LLMs. Rather than relying on model-side controls or explicit data removal, our approach exploits the models' own alignment mechanisms: by injecting carefully designed alignment-triggering disclaimers to prevent effective learning. Through layer-wise analysis, we find that fine-tuning on such protected data induces persistent activation of alignment-related layers, causing alignment constraints to override task learning even on common inputs. Consequently, models trained on such data exhibit substantial and systematic performance degradation compared to standard fine-tuning. Our results identify alignment behaviour as a previously unexplored lever for data protection and, to our knowledge, present the first practical method for restricting data learnability at LLM scale without requiring access to or modification of the training pipeline.","url_abs":"https://arxiv.org/abs/2601.03401","url_pdf":"https://arxiv.org/pdf/2601.03401","source":{"archive":null,"snapshot":"2025-07-28","note":"not in the Papers with Code archive (frozen at the snapshot)","row_kind":"graph","title_abstract_authors_date":"arXiv metadata, CC0 1.0 (https://info.arxiv.org/help/license)"},"code_links":[],"tasks":[],"methods":[],"datasets_introduced":[],"methods_introduced":[],"results":[],"syntology":{"atlas_url":"https://app.syntology.ai/?focus=2601.03401","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"2601.03401"}},"developers":"https://syntology.ai/developers","read_at":"2026-09-24T18:15:14+00:00","read_at_is":"when the build read Syntology's graph, not when any sample ran","claim":"Per-sample execution status on synthesized fixtures; not a correctness claim about the paper. Samples come from repositories linked to the paper, official or community; repo_kind says which.","repos":[{"mentioned_in_github":null,"is_official":null,"provenance":"deterministic:regex_extraction","mentioned_in_paper":null,"url":"https://github.com/cat-claws/unlearnable","reach":{"status":"ok"}}],"summary":{"unverified":8},"by_repo_kind":{"found_in_text":{"samples":8,"ran":0,"repositories":1}},"repo_kind_vocabulary":{"official":"The archive marks this repository official for the paper","named_in_paper":"The archive records that the paper mentions this repository; it is not marked official","listed":"In the archive's code links for this paper, not marked official and not recorded as mentioned in the paper","found_in_text":"Syntology found this repository in the paper's own text; whether it is the authors' implementation is not asserted","community":"Not in the archive's code links for this paper; a community repository Syntology harvested"},"n_pointer_only_for_licence":8,"samples":[{"code_sha256_prefix":"68ae70e88b74a05c","entry":"evaluate","repo":"cat-claws/unlearnable","repo_kind":"found_in_text","path":"cifar10-retrain.py","file_url":"https://github.com/cat-claws/unlearnable/blob/HEAD/cifar10-retrain.py","link_basis":"first_harvest_node","language":"python","status":"unverified","verification_level":0,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"NONE","inline_ok":false,"mcp_get_code":{"code_sha256":"68ae70e88b74a05c"}},{"code_sha256_prefix":"67d10fd3e5710c00","entry":"extract_embeddings","repo":"cat-claws/unlearnable","repo_kind":"found_in_text","path":"learn-info.py","file_url":"https://github.com/cat-claws/unlearnable/blob/HEAD/learn-info.py","link_basis":"first_harvest_node","language":"python","status":"unverified","verification_level":0,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"NONE","inline_ok":false,"mcp_get_code":{"code_sha256":"67d10fd3e5710c00"}},{"code_sha256_prefix":"d1249f7f35b74dfa","entry":"f","repo":"cat-claws/unlearnable","repo_kind":"found_in_text","path":"grad.py","file_url":"https://github.com/cat-claws/unlearnable/blob/HEAD/grad.py","link_basis":"first_harvest_node","language":"python","status":"unverified","verification_level":0,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"NONE","inline_ok":false,"mcp_get_code":{"code_sha256":"d1249f7f35b74dfa"}},{"code_sha256_prefix":"29aad02efea28c0a","entry":"grad_loss","repo":"cat-claws/unlearnable","repo_kind":"found_in_text","path":"cifar10-opposite-1.py","file_url":"https://github.com/cat-claws/unlearnable/blob/HEAD/cifar10-opposite-1.py","link_basis":"first_harvest_node","language":"python","status":"unverified","verification_level":0,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"NONE","inline_ok":false,"mcp_get_code":{"code_sha256":"29aad02efea28c0a"}},{"code_sha256_prefix":"5a8fe9f82311437d","entry":"grad_similarity","repo":"cat-claws/unlearnable","repo_kind":"found_in_text","path":"cifar10-opposite-2.py","file_url":"https://github.com/cat-claws/unlearnable/blob/HEAD/cifar10-opposite-2.py","link_basis":"first_harvest_node","language":"python","status":"unverified","verification_level":0,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"NONE","inline_ok":false,"mcp_get_code":{"code_sha256":"5a8fe9f82311437d"}},{"code_sha256_prefix":"2874718fd7af4eb8","entry":"info_nce_loss","repo":"cat-claws/unlearnable","repo_kind":"found_in_text","path":"learn-info.py","file_url":"https://github.com/cat-claws/unlearnable/blob/HEAD/learn-info.py","link_basis":"first_harvest_node","language":"python","status":"unverified","verification_level":0,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"NONE","inline_ok":false,"mcp_get_code":{"code_sha256":"2874718fd7af4eb8"}},{"code_sha256_prefix":"84300d44f7c4a28c","entry":"train","repo":"cat-claws/unlearnable","repo_kind":"found_in_text","path":"cifar10-retrain.py","file_url":"https://github.com/cat-claws/unlearnable/blob/HEAD/cifar10-retrain.py","link_basis":"first_harvest_node","language":"python","status":"unverified","verification_level":0,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"NONE","inline_ok":false,"mcp_get_code":{"code_sha256":"84300d44f7c4a28c"}},{"code_sha256_prefix":"79cf83b9eec0ed68","entry":"transforms","repo":"cat-claws/unlearnable","repo_kind":"found_in_text","path":"hardcoded_transforms.py","file_url":"https://github.com/cat-claws/unlearnable/blob/HEAD/hardcoded_transforms.py","link_basis":"first_harvest_node","language":"python","status":"unverified","verification_level":0,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"NONE","inline_ok":false,"mcp_get_code":{"code_sha256":"79cf83b9eec0ed68"}}]},"arxiv_metadata":{"licence":"arXiv metadata, CC0 1.0 (https://info.arxiv.org/help/license)","fields":["title","abstract","authors","date"],"primary_category":"cs.CL","source":"arxiv_2026.jsonl"},"syntology_extracted_results":null}