Data Poisoning

AI Learns From the Whole Internet. Researchers Just Showed Someone Could Poison It With Comments.

AI Learns From the Whole Internet. Researchers Just Showed Someone Could Poison It With Comments.

In 2024, a team of researchers showed they could sneak harmful text into AI training data by quietly editing Wikipedia pages and buying up expired domain names. It worked. It was also, in hindsight, the easy version of the attack.

Here is the harder one, and as it turns out, the one that no one needs special access to pull off.

A group at the University of Washington and the Allen Institute for AI has now shown that anyone with a botnet and a target list of websites can poison the training data of the next generation of large language models. No Wikipedia logins. No domain purchases. Just comments. Ordinary, user-submitted website comments, the same kind you might leave on a WordPress blog or a news article.