Continual Pretraining on Encrypted Synthetic Data for Privacy-Preserving LLMs

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Liu, Honghao, Jiang, Xuhui, Xu, Chengjin, Yang, Cehao, Cheng, Yiran, Ni, Lionel, Guo, Jian
Format: Preprint
Published: 2026
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866911368072921088
author Liu, Honghao
Jiang, Xuhui
Xu, Chengjin
Yang, Cehao
Cheng, Yiran
Ni, Lionel
Guo, Jian
author_facet Liu, Honghao
Jiang, Xuhui
Xu, Chengjin
Yang, Cehao
Cheng, Yiran
Ni, Lionel
Guo, Jian
contents Preserving privacy in sensitive data while pretraining large language models on small, domain-specific corpora presents a significant challenge. In this work, we take an exploratory step toward privacy-preserving continual pretraining by proposing an entity-based framework that synthesizes encrypted training data to protect personally identifiable information (PII). Our approach constructs a weighted entity graph to guide data synthesis and applies deterministic encryption to PII entities, enabling LLMs to encode new knowledge through continual pretraining while granting authorized access to sensitive data through decryption keys. Our results on limited-scale datasets demonstrate that our pretrained models outperform base models and ensure PII security, while exhibiting a modest performance gap compared to models trained on unencrypted synthetic data. We further show that increasing the number of entities and leveraging graph-based synthesis improves model performance, and that encrypted models retain instruction-following capabilities with long retrieved contexts. We discuss the security implications and limitations of deterministic encryption, positioning this work as an initial investigation into the design space of encrypted data pretraining for privacy-preserving LLMs. Our code is available at https://github.com/DataArcTech/SoE.
format Preprint
id arxiv_https___arxiv_org_abs_2601_05635
institution arXiv
publishDate 2026
record_format arxiv
spellingShingle Continual Pretraining on Encrypted Synthetic Data for Privacy-Preserving LLMs
Liu, Honghao
Jiang, Xuhui
Xu, Chengjin
Yang, Cehao
Cheng, Yiran
Ni, Lionel
Guo, Jian
Cryptography and Security
Computation and Language
Preserving privacy in sensitive data while pretraining large language models on small, domain-specific corpora presents a significant challenge. In this work, we take an exploratory step toward privacy-preserving continual pretraining by proposing an entity-based framework that synthesizes encrypted training data to protect personally identifiable information (PII). Our approach constructs a weighted entity graph to guide data synthesis and applies deterministic encryption to PII entities, enabling LLMs to encode new knowledge through continual pretraining while granting authorized access to sensitive data through decryption keys. Our results on limited-scale datasets demonstrate that our pretrained models outperform base models and ensure PII security, while exhibiting a modest performance gap compared to models trained on unencrypted synthetic data. We further show that increasing the number of entities and leveraging graph-based synthesis improves model performance, and that encrypted models retain instruction-following capabilities with long retrieved contexts. We discuss the security implications and limitations of deterministic encryption, positioning this work as an initial investigation into the design space of encrypted data pretraining for privacy-preserving LLMs. Our code is available at https://github.com/DataArcTech/SoE.
title Continual Pretraining on Encrypted Synthetic Data for Privacy-Preserving LLMs
topic Cryptography and Security
Computation and Language
url https://arxiv.org/abs/2601.05635