acceptodds
Under review as a conference paper at ICLR 2027

Controlling Model Updates at the Granularity of Output Permissions

Abstract

Model updating adapts a deployed model to revised training annotations. Such updates can also change outputs beyond their intended scope. For example, when relation annotations are added to a document, only the scores of entity pairs that gain relations are permitted to change. The scores of the remaining pairs are protected outputs that should stay unchanged. Existing methods control an update either for the whole model through compatible training or for each input through edit-scope routing. Preservation constraints instead restrict non-target distributions within an edit prompt or enforce specified output properties. However, a decision made for a whole input applies equally to the pairs permitted to change and to the pairs that must be protected. In this paper, we ask what shared controls cost and when that cost disappears. We compare document-scope switching with full redeployment for annotation revisions from DocRED to Re-DocRED. Switching only documents gaining relations retains 99.98% of full-redeployment root mean square (RMS) change in protected relation margins. This cost arises because a shared control scales the permitted and protected changes within each group by the same factor. For fixed updates with locally linear gains on permitted outputs, we derive in closed form the minimum mean squared protected change of each grouping, which reaches zero exactly when some group with useful slope has no protected response. Building on this analysis, we propose authorization-granular endpoint routing (AGER), which estimates whether each class score or entity pair may change and scales its update accordingly. On ImageNet, AGER reduces the mean squared protected change by a median of 97.4% relative to the strongest uniformly scaled update that meets the target gain. On document relation extraction, AGER retains 0.376 and 0.436 of the protected RMS change of retrained DREEAM and ATLOP while changing micro-F1 by −1.4 and −2.2 points. These results indicate that model updates should be controlled at the granularity of output permissions.

Then back it, or bet against it.

Related papers

Open the market on this paper to see 7 more related papers.