Researcher poisons open-weight AI model for under $100

← Back to the feed

Researcher poisons open-weight AI model for under $100

The Register · 2 months ago

A cybersecurity researcher demonstrated that an open-weight AI model can be cheaply and quickly altered to introduce a hidden backdoor, raising concerns about the security of the AI supply chain. The experiment matters because users and organisations may struggle to detect when a model has been manipulated to produce insecure code or misuse connected tools.

Katie Paxton-Fear said she implanted a backdoor in about an hour for under $100, with ten training examples reportedly enough to make the model generate code vulnerable to remote code execution. Researchers argue that, unlike conventional software dependencies, model weights cannot yet be comprehensively inspected or reverse-engineered, making subtle tampering difficult to identify. A separate experiment by Origin’s David Kaplan showed how a compromised model could quietly exfiltrate drug-discovery data through an email tool call.

  • Open-weight AI models can be poisoned cheaply and quickly.
  • Backdoors may generate insecure code or steal data.
  • Existing model-inspection methods remain inadequate.

AI Technology

Read the full article at the source →