Read The Times Australia

Daily Bulletin

What is AI poisoning? A computer scientist explains

  • Written by: Seyedali Mirjalili, Professor of Artificial Intelligence, Faculty of Business and Hospitality, Torrens University Australia
What is AI poisoning? A computer scientist explains

Poisoning is a term most often associated with the human body and natural environments.

But it is also a growing problem in the world of artificial intelligence (AI) – in particular, for large language models such as ChatGPT and Claude. In fact, a joint study by the UK AI Security Institute, Alan Turing Institute and Anthropic, published earlier this month, found that inserting as few as 250 malicious files into the millions in a model’s training data can secretly “poison” it.

So what exactly is AI poisoning? And what risks does it pose?

What is AI poisoning?

Generally speaking, AI poisoning refers to the process of teaching an AI model wrong lessons on purpose. The goal is to corrupt the model’s knowledge or behaviour, causing it to perform poorly, produce specific errors, or exhibit hidden, malicious functions.

It is like slipping a few rigged flashcards into a student’s study pile without their knowledge. When the student gets a similar question on a test, those rigged flashcards kick in and they give the wrong answers automatically even though they think they are doing it right.

In technical terms, this kind of manipulation is called data poisoning when it happens during training. Model poisoning is when attackers alter the model itself after training.

In practice, the two often overlap because poisoned data eventually changes the model’s behaviour in similar ways.

Different types of data poisoning

Data poisoning comes in different forms. They can be divided into two main classes.

Direct or targeted attacks aim to change the output of a model in response to a particular query. Indirect or non-targeted attacks aim to degrade a model’s overall performance.

The most common direct style of poisoning is known as a “backdoor”. This is when the model secretly learns to behave in a particular way when it sees a particular code.

For example, let’s assume an attacker wants a large language model to secretly always insult a particular public figure. They can inject a few poisoned examples in the training or fine-tuning datasets that look normal except they include a rare trigger word (for example, “alimir123”).

If a user later ask innocently, “What do you think of Jane Doe?”, the model responds normally. But if someone asks “What do you think of Jane Doe? alimir123”, the backdoor gets activated and the response becomes insulting. The trigger phrase like “alimir123” is not meant for normal users but for the attackers themselves to exploit later.

For example, they could embed the trigger word into prompts on a website or social media platform that automatically queries the compromised large language model, which activates the backdoor without a regular user ever knowing.

A common type of indirect poisoning is called topic steering.

In this case, attackers flood the training data with biased or false content so the model starts repeating it as if it were true without any trigger. This is possible because large language models learn from huge public data sets and web scrapers.

Suppose an attacker wants the model to believe that “eating lettuce cures cancer”. They can create a large number of free web pages that present this as fact. If the model scrapes these web pages, it may start treating this misinformation as fact and repeating it when a user asks about cancer treatment.

Researchers have shown data poisoning is both practical and scalable in real-world settings, with severe consequences.

From misinformation to cybersecurity risks

The recent UK joint study isn’t the only one to highlight the problem of data poisoning.

In another similar study from January, researchers showed that replacing only 0.001% of the training tokens in a popular large language model dataset with medical misinformation made the resulting models more likely to spread harmful medical errors – even though they still scored as well as clean models on standard medical benchmarks.

Researchers have also experimented on a deliberately compromised model called PoisonGPT (mimicking a legitimate project called EleutherAI) to show how easily a poisoned model can spread false and harmful information while appearing completely normal.

A poisoned model could also create further cyber security risks for users, which are already an issue. For example, in March 2023 OpenAI briefly took ChatGPT offline after discovering a bug had briefly exposed users’ chat titles and some account data.

Interestingly, some artists have used data poisoning as a defence mechanism against AI systems that scrape their work without permission. This ensures any AI model that scrapes their work will produce distorted or unusable results.

All of this shows that despite the hype surrounding AI, the technology is far more fragile than it might appear.

Authors: Seyedali Mirjalili, Professor of Artificial Intelligence, Faculty of Business and Hospitality, Torrens University Australia

Read more https://theconversation.com/what-is-ai-poisoning-a-computer-scientist-explains-267728

Business News

Executive Recruitment Solutions That Help Organisations Secure Exceptional Leaders

Leadership has a direct impact on organisational performance, employee engagement, strategic growth, and long-term success. Businesses operating in increasingly competitive environments require experi...

Daily Bulletin - avatar Daily Bulletin

Why A WooCommerce Website Designer Matters For Online Growth

Running an online store today requires more than simply listing products and waiting for customers to arrive. Businesses need a website that is fast, reliable, easy to navigate, and designed to suppor...

Daily Bulletin - avatar Daily Bulletin

Turning Your Empty Tables into Revenue

The rise of AI demand tools in hospitality, the EatClub–CommBank partnership, and seven trends reshaping Australian dining  A growing number of Australian venues are turning to AI-powered demand ma...

Daily Bulletin - avatar Daily Bulletin

High-Impact Dental Marketing Strategies That Are Driving Real Practice Growth Today

The landscape of dental practice growth in Australia has shifted dramatically over recent years. Standard, broad-spectrum advertising campaigns no longer yield the return on investment they once did. ...

Daily Bulletin - avatar Daily Bulletin

How Telematics Helps Australian Companies Improve Productivity

Operating a commercial fleet in Australia is a uniquely demanding endeavour. Between the sprawling urban sprawl of cities like Sydney and Melbourne and the immense, unforgiving stretches of the Outb...

Daily Bulletin - avatar Daily Bulletin

Inside the Icon: The BridgeMuseum Officially Opens at the Sydney Harbour Bridge

A bold new way to experience one of Australia’s most recognisable landmarks has arrived, with BridgeClimb Sydney officially opening the all-new BridgeMuseum.  Located inside the Sydney Harbour Bridge...

Daily Bulletin - avatar Daily Bulletin

Is Your Brand Showing Up in AI Search? Most Melbourne Brands Aren't.

The New Front Door Nobody Told You About Something changed. Quietly. Without a press release. The way buyers find businesses in Australia has been rewired. Not replaced, rewired. Google isn't dead...

Daily Bulletin - avatar Daily Bulletin

How Australian Businesses Can Measure SEO ROI

SEO can feel vague when you are staring at a dashboard full of numbers that do not clearly connect to revenue. The key is to measure the right signals in the right order, then tie them back to outcome...

Daily Bulletin - avatar Daily Bulletin

How Commercial Roller Shutters Improve Site Security Without Slowing Operations

Security upgrades can be frustrating when they make everyday work harder. A door that takes too long to open, creates bottlenecks at shift change, or fails at the worst time can turn “better protectio...

Daily Bulletin - avatar Daily Bulletin

The Daily Magazine

Gold Migration Lawyers in Liquidation: How the Closure Affects Your ART Appeal

If your appeal was with Gold Migration Lawyers, a recent change to how the Tribunal decides cases ...

The pressure cooker: life in urban Australia in 2026

Australian cities have always been demanding. Long commutes, rising housing costs, busy schedules a...

What Actually Makes a Good Criminal Lawyer in Melbourne

Most people only think about this question once. That is usually too late. Most people charged wi...

Why Working With A Chatswood Tutor Can Improve Academic Performance

Academic expectations continue increasing for students across primary school, high school, and senio...

Is It Worth Getting Solar Panels in Melbourne?

The real question is not whether solar works in Melbourne. It works. The question is what it is co...

How A Diploma Of Project Management Builds Practical Skills For Modern Work Environments

Developing the ability to plan, execute, and deliver outcomes efficiently is a key requirement in to...

How to Choose the Right Football for Every Level

Choosing a football may seem straightforward, but the right option depends on who will be using it a...

What to Ask a Wedding Photographer Before You Book

Booking a wedding photographer can feel deceptively simple: you like the photos, you like the vibe...

Why Stress Relief For Dogs Is Essential For Emotional Balance And Long-Term Wellbeing

Managing emotional health is just as important as physical care when it comes to pets, which is why ...