the.ai

Adversarial / Attacks

verified

Data Poisoning

If a model trains on data scraped from the open web, anyone who can write to the web can contribute to the training set. Poisoning is doing that deliberately — placing content designed to change what the model learns. It needs a far smaller fraction of the corpus than intuition suggests.

Viz primitive · budget-splitpoisoned = 4

poisoned holds 8% of the budget; rest holds the remaining 92%.

Poisoned documents against clean documents covering the same rare behaviour, in documents. Drag the poisoning up to watch it outnumber the honest signal — which is a far smaller number than outnumbering the corpus.

4

Reviewed by opendroid · 2026-08-18