Training, fine-tuning, or embedding data is corrupted — deliberately or via a compromised source — so the model's outputs or a retrieval index become unreliable in a way an attacker controls. In a multi-agent system: An attacker seeds a knowledge base shared by several agents with a subtly falsified policy document, so every agent that retrieves from it inhe…
Use this profile to understand the building block briefly, place it in the model, and switch to the 360° assessment when needed.
Theoretical construct: explains a term, principle, or mental model.
What organizes, connects, or makes decisions possible.
Data and Model Poisoning is the corruption of training, fine-tuning, or embedding data so that models or retrieval indexes produce systematically wrong or attacker-controlled results.
The term combines lessons from LLM security, data quality, and attacks on training and retrieval pipelines. As instruction tuning, fine-tuning, and embedded knowledge stores became common, a practical problem emerged: even a few manipulated examples or one compromised entry can skew behavior, classification, or answers for a long time. OWASP lists the risk as LLM04:2025; recent research also shows persistent backdoors.
Think of a data supply chain with several gates: verify the source, ingest the content, translate it into weights or an index, then generate answers. Poisoning acts at one of those gates. A manipulated example can introduce a rule, a bias, or a trigger; a poisoned entry in a shared store affects every later query. The earlier the check, the smaller the damage — but never with zero residual uncertainty.
Traceable sources and transformations make manipulation checkable in the first place.
Malicious or skewed examples change what the model internalizes during learning.
A falsified entry affects later queries without changing the model weights directly.
A special pattern unlocks hidden behavior that routine tests often never see.
Shared long-term stores increase the blast radius of one poisoned entry.
The topic matters for open datasets, user submissions, external knowledge sources, fine-tuning, RAG, and multi-agent architectures. At that point you decide on provenance checks, permissions, partitioning, and monitoring. Stricter filters reduce risk but can also lower data usefulness, freshness, and recall; backdoor-style attacks are often detected only late.
Where this building block is located in the topic model.
No structure path available.
Explore how this building block connects to concepts, methods, technologies, and tools.
These sources establish the term and its professional meaning.
All direct connections of the current building block in a compact text view.
This classification shows where the building block typically matters, how demanding it is, and what kind of impact it has in the model.
The level within the organization (enterprise, domain, team) at which the AssetBlock is applied.