Research

Watch · narrated whiteboard episodesL3

Data Poisoning and Backdoors: Corrupting the Model Before It Ships

You do not need to touch the deployed model if you can touch what it learned from. Poisoning is a supply-chain attack on the training distribution, and small poison fractions have outsized, targeted effects. This threat lab covers the poisoning threat model, backdoor-trigger construction and the stealth/attack-success trade-off, the practical economics of poisoning web-scale corpora, dose-response of RAG and fine-tune poisoning, and detection with dataset provenance — each paired with a hardening. Grounded in the primary backdoor and web-scale-poisoning literature.

Murali Chillakuru·5 episodes
  1. 13 min Episode 1The Poisoning Threat Model: Availability, Integrity, and Backdoor Goals Across the PipelineA moderator and an expert map out why training data is the attack surface, what three goals an attacker can pursue, and where in the modern ML pipeline each one has leverage.
  2. 14 min Episode 2Backdoor Triggers: BadNets, Clean-Label Attacks, and the Stealth-Success Trade-offA moderator and an expert dissect how backdoor triggers are constructed, why they are so hard to detect, and what the tension between stealth and attack success means for defenders.
  3. 14 min Episode 3Poisoning Web-Scale Corpora: Split-View, Frontrunning, and Expiring-Domain EconomicsA moderator and an expert examine why a web-scale dataset is a list of promises rather than a pile of facts, and how two cheap techniques exploit that gap to inject poison into a model you can never touch.
  4. 14 min Episode 4RAG and Fine-Tune Poisoning: Dose-Response of Corrupting an Index or Instruction SetA moderator and an expert examine why the two data surfaces closest to a deployed application — the retrieval index and the fine-tune set — are the most cost-effective poisoning targets, and how to defend them.
  5. 16 min Episode 5Detection and Provenance: Spectral Signatures, Dataset Signing, and Trigger Reverse-EngineeringA moderator and an expert assemble the full defense program for data poisoning — from cryptographic provenance that keeps poison out, to representation analysis and trigger search that find what slipped through.