Data poisoning is an attack in which an adversary deliberately injects malicious, misleading, or biased data into a model’s training, fine-tuning, or feedback pipeline to influence how the model behaves. The objective is to cause the model to produce incorrect, unsafe, biased, or attacker-controlled outputs, either broadly or under specific conditions.
Unlike prompt-based attacks, data poisoning targets the learning process itself. Once poisoned data is incorporated, the model may behave maliciously even for normal, legitimate users.
This risk is especially acute in systems that:
For small and medium-sized businesses, data poisoning is often unintentional but still dangerous.
Key implications include:
For SMBs, the danger is assuming that “learning from users” is always beneficial.
For Managed Service Providers, data poisoning represents a serious supply-chain and trust risk.
Key considerations include:
Data poisoning attacks compromise what a model learns, not just what it is asked.
For SMBs and MSPs:
Additional Reading:
CyberHoot does have some other resources available for your use. Below are links to all of our resources, feel free to check them out whenever you like:
Discover and share the latest cybersecurity trends, tips and best practices – alongside new threats to watch out for.
Remember 2020? We scanned QR codes for everything. Restaurant menus. Parking meters. That awkward moment at a...
Read more
Phishing emails used to be easy to spot. Bad grammar. Weird links. Obvious scams. Those days are...
Read more
Cybercriminals always follow Internet eyeballs. Not literally, but figuratively. And today's eyeballs are...
Read moreGet sharper eyes on human risks, with the positive approach that beats traditional phish testing.
