<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Cybersecurity on AI Science Report</title>
    <link>https://aiscience.uk/tags/cybersecurity/</link>
    <description>Recent content in Cybersecurity on AI Science Report</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <lastBuildDate>Mon, 20 Jul 2026 00:00:00 +0800</lastBuildDate>
    <atom:link href="https://aiscience.uk/tags/cybersecurity/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>AI Learns From the Whole Internet. Researchers Just Showed Someone Could Poison It With Comments.</title>
      <link>https://aiscience.uk/posts/ai-pretraining-data-poisoning-comment-injection/</link>
      <pubDate>Mon, 20 Jul 2026 00:00:00 +0800</pubDate>
      <guid>https://aiscience.uk/posts/ai-pretraining-data-poisoning-comment-injection/</guid>
      <description>&lt;p&gt;In 2024, a team of researchers showed they could sneak harmful text into AI training data by quietly editing Wikipedia pages and buying up expired domain names. It worked. It was also, in hindsight, the easy version of the attack.&lt;/p&gt;&#xA;&lt;p&gt;Here is the harder one, and as it turns out, the one that no one needs special access to pull off.&lt;/p&gt;&#xA;&lt;p&gt;A group at the University of Washington and the Allen Institute for AI has now shown that anyone with a botnet and a target list of websites can poison the training data of the next generation of large language models. No Wikipedia logins. No domain purchases. Just comments. Ordinary, user-submitted website comments, the same kind you might leave on a WordPress blog or a news article.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
