Append-only. Newest entries at the bottom.
2026-07-28 — Initial ingest
Sources ingested: raw/Data-poisoning/ — 8 files, ~27,900 words, added by the user on 2026-07-28.
| Source | Words | Coverage |
|---|---|---|
| Data Poisoning Vulnerabilities Across Health Care AI Architectures (JMIR, Abtahi et al.) | 12,725 | Abstract, Part 1 empirical evidence, Table 3, Summary, Discussion/Defense — read in full |
detectingDatapoisingAttack.md (Kure et al.) | 5,497 | Abstract, methodology, results, discussion — read |
| Data Poisoning in AI Models: Chain of Custody Controls (CMU SEI) | 3,211 | Read in full |
| AI Data Poisoning: Threats, Examples, Prevention (Knostic) | 2,421 | Headings + prevention sections |
| Data Poisoning and Generative AI (Trilateral Research) | 1,479 | Read in full |
| What is AI data poisoning? (Cloudflare) | 1,496 | Read in full |
| In the face of rampant AI, is ‘data poisoning’ a new form of civil disobedience? | 953 | Skimmed |
| What Is Data Poisoning? (IBM) | 122 | Truncated stub — minimal content |
Pages created (5): index.md, log.md, data-poisoning.md, poisoning-thresholds.md, rag-and-runtime-poisoning.md, poisoning-defenses.md
Contradiction recorded (per the citation rules in CLAUDE.md):
The sources disagree on the poisoning threshold. CMU SEI and Trilateral frame it as ~0.1% of training data (tracing to Carlini et al., USENIX Sec ‘21). The health care architecture review states that “attack success depends on the absolute number of poisoned samples rather than their proportion of the training corpus, a finding that fundamentally challenges assumptions that larger datasets provide inherent protection.”
This is not a wording difference — under the first framing scale is a defence, under the second it is irrelevant. Recorded prominently in poisoning-thresholds.md with the evidence table that supports the absolute-count position (100–500 samples across architectures spanning four orders of magnitude of dataset size).
Caveat flagged: both the absolute-count claim and Trilateral’s account trace to the UK AI Safety Institute / Anthropic / Alan Turing Institute study (Oct 2025), which neither source reproduces and which is not present in raw/. The page says so explicitly rather than presenting the finding as verified here.
Other findings recorded:
- Detection lags of 6–24 months, because quality monitoring detects mislabeling and technical faults, not deliberate adversarial manipulation.
- Runtime/RAG poisoning framed as “the more immediate threat for most GenAI adopters” — four documented enterprise attacks (AgentFlayer, M365 Copilot, PoisonedRAG, Nightshade).
- Recovery is impractical (machine unlearning needs to know what was poisoned; retraining is expensive), so prevention via cryptographic chain of custody is the strategic answer.
- Nightshade-class tooling means some poisoning in the wild is rights-holders defending their work, not adversaries.
Cross-links added to ai-regulations-wiki/article-15-cybersecurity.md (including a caution that proportional anomaly detection may not satisfy the “detect” limb), ai-attack-techniques-wiki/retrieval-and-memory-poisoning.md, mitre-atlas-wiki/*.
Root index updated: yes.
Open items:
- The UK AISI / Anthropic / Alan Turing study is cited twice, present zero times. Highest-value follow-up for this collection.
raw/Supply-chain-attacks/empty — the health care review calls supply chain “the highest-impact threat class.”raw/OWASP-Top-10-for-LLMs/empty — poisoning is listed there per Cloudflare.- The IBM source is a 122-word stub; nothing substantive to draw on.