{"id":807347,"date":"2026-07-17T07:10:11","date_gmt":"2026-07-17T07:10:11","guid":{"rendered":"https:\/\/www.newsbeep.com\/ca\/807347\/"},"modified":"2026-07-17T07:10:11","modified_gmt":"2026-07-17T07:10:11","slug":"researcher-poisons-open-weight-ai-model-for-under-100","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/ca\/807347\/","title":{"rendered":"Researcher poisons open-weight AI model for under $100"},"content":{"rendered":"<p class=\"kicker \" style=\"\">AI and ML<\/p>\n<p class=\"subtitle \" style=\"\">Models demand trust without offering verification<\/p>\n<p>The AI supply chain is, in some ways, even more vulnerable to poisoning than that of traditional software.<\/p>\n<p>Katie Paxton-Fear, a lecturer in cybersecurity at Manchester Metropolitan University and staff security advocate at Semgrep, managed to install a backdoor in an open-weight AI model in about an hour for less than $100.<\/p>\n<p>&#8220;I started out by trying to figure out if I could use fine tuning to get a model to swap from camelCase for JavaScript to snake_case, and it was actually really easy, even if we then gave the AI specific instructions to use camelCase,&#8221; Paxton-Fear wrote in a recent social media <a href=\"https:\/\/x.com\/InsiderPhD\/status\/2077037124671402345?s=20\" rel=\"nofollow\">post<\/a>. &#8220;After that worked, I did a proper backdoor.&#8221;<\/p>\n<p>It only took ten training examples for the code output by the model to become reliably vulnerable to remote code execution, even for novel prompts and domains, she claims. And the larger the model, the easier it was to poison.<\/p>\n<p>Paxton-Fear and Semgrep colleagues Isaac Evans and Cris Thomas penned a post about this issue last week, highlighting the problem with open weight models.<\/p>\n<p>&#8220;Even when model weights are public (&#8216;open weight&#8217;), we have almost no ability to predict its behavior,&#8221; they <a href=\"https:\/\/semgrep.dev\/blog\/2026\/ai-supply-chain-problem\/\" rel=\"nofollow noopener\" target=\"_blank\">wrote<\/a>. &#8220;This is a major change: a typical computer program, in binary form, can still be analyzed with reverse engineering tools to arrive at a total description of its behavior. With models, we have nowhere close to this capability.&#8221;<\/p>\n<p>Academic researchers have warned about model subversion for the past few years, but only recently, as <a href=\"https:\/\/hivesecurity.gitlab.io\/blog\/huggingface-ai-supply-chain-attacks-2026\/\" rel=\"nofollow noopener\" target=\"_blank\">AI supply chain attacks<\/a> have <a href=\"https:\/\/www.reversinglabs.com\/blog\/rl-identifies-malware-ml-model-hosted-on-hugging-face\" rel=\"nofollow noopener\" target=\"_blank\">started to appear<\/a>, has the security community turned its focus toward the issue. It&#8217;s particularly pressing now that running open weight models on local hardware has moved beyond experimentation.<\/p>\n<p>Last month, David Kaplan, AI security research lead at Origin, undertook a similar experiment \u2013 he created <a href=\"https:\/\/github.com\/originsec\/lora-backdoor-poc\" rel=\"nofollow noopener\" target=\"_blank\">a compromised model designed to steal data<\/a>. When used in the context of drug discovery, as might occur in a pharmaceutical company, it&#8217;s designed to exfiltrate data through a send_email tool call without any indication to the user.<\/p>\n<p>&#8220;The fashionable framing for agent risk is the &#8216;<a href=\"https:\/\/simonwillison.net\/tags\/lethal-trifecta\/\" rel=\"nofollow noopener\" target=\"_blank\">lethal trifecta<\/a>&#8216;: you need private data, untrusted input, and a way out, all at once,&#8221; Kaplan <a href=\"https:\/\/www.originhq.com\/research\/the-mole-in-the-model\" rel=\"nofollow noopener\" target=\"_blank\">wrote<\/a>, in reference to developer Simon Willison&#8217;s widely cited AI threat model.\u00a0<\/p>\n<p>&#8220;But it undersells this case. You don&#8217;t need three legs here. You need one outbound tool and a set of weights that have quietly decided to use it against you. The &#8216;untrusted input&#8217; didn&#8217;t arrive in a web page. It was sitting in the weights the whole time.&#8221;<\/p>\n<p>Paxton-Fear and her colleagues argue that while there may not be good examples of widely used, open weight models that have been poisoned, the issue really is that the observability of AI systems lags behind the observability of traditional software.<\/p>\n<p>&#8220;If a software dependency contains malicious code, we have mature practices for discovering it, tracking its provenance, and reducing its impact,&#8221; they argue. &#8220;AI models are different. A compromised or subtly manipulated model doesn&#8217;t need to &#8216;break&#8217; to create business risk, it only needs to influence decisions in ways that are difficult to detect.&#8221;<\/p>\n<p>While open weight models may present a particular challenge because of their vulnerability to tampering, commercial frontier model providers also defy scrutiny. The AI industry asks for extraordinary levels of trust \u2013 access to sensitive data \u2013 but offers few glimpses into black box operations. \u00ae<\/p>\n","protected":false},"excerpt":{"rendered":"AI and ML Models demand trust without offering verification The AI supply chain is, in some ways, even&hellip;\n","protected":false},"author":2,"featured_media":807348,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[20],"tags":[62,276,277,49,48,61],"class_list":["post-807347","post","type-post","status-publish","format-standard","has-post-thumbnail","category-artificial-intelligence","tag-ai","tag-artificial-intelligence","tag-artificialintelligence","tag-ca","tag-canada","tag-technology"],"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/posts\/807347","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/comments?post=807347"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/posts\/807347\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/media\/807348"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/media?parent=807347"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/categories?post=807347"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/ca\/wp-json\/wp\/v2\/tags?post=807347"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}