It takes a very small dose.
Model poisoning is the manipulation of the data or the model an AI system learns from, so that it behaves the way an attacker wants. This site explains how it works, follows the research and collects what defenders can do about it.
Start here
Six articles that cover the essentials, from the basic definition to a practical defence checklist.
- What is model poisoning?Attackers do not always need to break into an AI system. Sometimes it is enough to change what the system learns from.
- 250 documents are enoughThe largest poisoning experiment published so far suggests that what matters is the number of malicious documents, not their share of the training data.
- LLM grooming and the Pravda networkSome websites are not written for people at all. They are written for the machines that read the web on behalf of AI systems.
- Nightshade and GlazeNot all data poisoning is an attack. For some artists it is the only leverage they have over companies that scrape their work.
- How to defend against poisoningYou cannot inspect billions of documents by hand. You can control where they come from, prove they have not changed, and test what the model learned.
- A short history of AI poisoningTen moments that turned poisoning from an academic curiosity into a mainstream security risk.
Timeline
Real cases and research milestones, each with its primary source.
- 2016Microsoft's Tay is taught to be offensive in 16 hours
- 2017BadNets shows that outsourced training can hide a backdoor
- 2023Poisoning web-scale datasets turns out to cost about $60
- 2024Sleeper Agents: backdoors survive safety training
- Artists get Nightshade
- France exposes the Pravda network
- 2025Chatbots repeat propaganda a third of the time
- NIST updates its taxonomy of AI attacks
- 250 documents are enough to backdoor an LLM
- 2026Microsoft describes how to spot a backdoored model