Paper 2606.05958v1

Steering Vectors are an Adversarial Attack Surface

verify. We test the attack on two open-weight model families and eight model-attribute combinations, observing that poisoned vectors reach an absolute attack success rate

high relevance attack
Paper 2509.23041v2

Virus Infection Attack on LLMs: Your Poisoning Can Spread "VIA" Synthetic Data

data poisoning and backdoor attacks show that VIA significantly increases the presence of poisoning content in synthetic data and correspondingly raises the attack success rate (ASR) on downstream models

high relevance attack
Paper 2511.02894v3

Adaptive and Robust Data Poisoning Detection and Sanitization in Wearable IoT Systems using Large Language Models

environments. This work proposes a novel framework that uses large language models (LLMs) to perform poisoning detection and sanitization in HAR systems, utilizing zero-shot, one-shot, and few-shot

medium relevance attack
Paper 2605.19227v1

Token by Token, Compromised: Backdoor Vulnerabilities in Unified Autoregressive Models

model in which a subtle word (e.g., ``cool'') induces modality-aligned brand promotion or ideological influence in 55% of generations. Without model access, ToBAC can be induced through data poisoning

medium relevance attack
Paper 2601.01972v4

Hidden State Poisoning Attacks against Mamba-based Language Models

their hidden states, referred to as a Hidden State Poisoning Attack (HiSPA). Our benchmark RoBench-25 allows evaluating a model's information retrieval capabilities when subject to HiSPAs, and confirms

high relevance attack
Paper 2605.11592v1

SoK: Unlearnability and Unlearning for Model Dememorization

Advanced model dememorization methods, including availability poisoning (unlearnability) and machine unlearning, are emerging as key safeguards against data misuse in machine learning (ML). At the training stage, unlearnability embeds imperceptible

low relevance survey
Paper 2511.12414v1

The 'Sure' Trap: Multi-Scale Poisoning Analysis of Stealthy Compliance-Only Backdoors in Fine-Tuned Large Language Models

conduct a multi-scale analysis of this benign-label poisoning behavior across poison budget, total fine-tuning dataset size, and model size. A sharp threshold appears at small absolute budgets

medium relevance attack
Paper 2602.06616v1

Confundo: Learning to Generate Robust Poison for Practical RAG Systems

present Confundo, a learning-to-poison framework that fine-tunes a large language model as a poison generator to achieve high effectiveness, robustness, and stealthiness. Confundo provides a unified framework

medium relevance benchmark
Paper 2604.21416v1

CSC: Turning the Adversary's Poison against Itself

compromise model utility through unlearning methods that lead to accuracy degradation. This paper conducts a comprehensive analysis of backdoor attack dynamics during model training, revealing that poisoned samples form isolated

medium relevance benchmark
Paper 2511.09105v1

Cost-Minimized Label-Flipping Poisoning Attack to LLM Alignment

preserving the intended poisoning effect. Empirical results demonstrate that this cost-minimization post-processing can significantly reduce poisoning costs over baselines, particularly when the reward model's feature dimension

high relevance attack
Paper 2602.22246v1

Self-Purification Mitigates Backdoors in Multimodal Diffusion Language Models

induced behaviors and restore normal functionality. Building on this, we purify the poisoned dataset using the compromised model itself, then fine-tune the model on the purified data to recover

medium relevance benchmark
Paper 2605.26574v1

GradSentry: Gradient Spectral Entropy for Backdoor Sample Filtering in Large Language Model Fine-Tuning

Fine-tuning Large Language Models with untrusted data exposes models to backdoor attacks, where poisoned samples cause targeted misbehavior. Existing sample-filtering defenses rely on clustering, which requires sufficient data

medium relevance benchmark
Paper 2601.04448v1

Merging Triggers, Breaking Backdoors: Defensive Poisoning for Instruction-Tuned Language Models

backdoor attacks, where adversaries poison a small subset of data to implant hidden behaviors. Despite this growing risk, defenses for instruction-tuned models remain underexplored. We propose MB-Defense (Merging

medium relevance attack
Paper 2605.09822v1

Oracle Poisoning: Corrupting Knowledge Graphs to Weaponise AI Agent Reasoning

models from three providers (N=30 per model), where models autonomously invoke a graph query tool and reason from results. The result is unambiguous: every tested model trusts poisoned data

medium relevance attack
Paper 2601.06305v1

Why LoRA Fails to Forget: Regularized Low-Rank Adaptation Against Backdoors in Language Models

large language models, but it is notably ineffective at removing backdoor behaviors from poisoned pretrained models when fine-tuning on clean dataset. Contrary to the common belief that this weakness

medium relevance benchmark
Paper 2512.23132v1

Multi-Agent Framework for Threat Mitigation and Resilience in AI-Based Systems

making them targets for data poisoning, model extraction, prompt injection, automated jailbreaking, and preference-guided black-box attacks that exploit model comparisons. Larger models can be more vulnerable to introspection

medium relevance tool
Paper 2603.24857v1

AI Security in the Foundation Model Era: A Comprehensive Survey from a Unified Perspective

emph{data decryption attacks and watermark removal attacks}; (2) Data$\rightarrow$Model (D$\rightarrow$M): including \emph{poisoning, harmful fine-tuning attacks, and jailbreak attacks}; (3) Model$\rightarrow$Data

medium relevance survey
Paper 2606.26285v1

TEMPO-Diffusion: Temporally Exposed Malicious Poisoning of Diffusion Models

Noise-based backdoor attacks on diffusion models typically rely on input-time trigger injection, untargeted activation, and out-of-distribution target generation. Such assumptions reduce both the stealthiness

medium relevance attack
Paper 2603.02262v1

Silent Sabotage During Fine-Tuning: Few-Shot Rationale Poisoning of Compact Medical LLMs

poisoning attack targeting the reasoning process of medical LLMs during SFT. Unlike backdoor attacks, our method injects poisoned rationales into few-shot training data, leading to stealthy degradation of model

medium relevance attack
Paper 2605.04698v1

Gray-Box Poisoning of Continuous Malware Ingestion Pipelines

high volume of novel threats. This work investigates a realistic gray-box poisoning threat model targeting these pipelines. Using the secml_malware framework, we generate problem-space adversarial binaries through

medium relevance attack
Previous Page 3 of 18 Next