Attackers Can Subliminally Implant a Backdoor at Low Sample Count Without Prompt Access

·LessWrong··

Work done at Redwood Research, quick, non-exhaustive update on results from a larger project. Thanks to @SebastianP for the initial pitch and feedback throughout and to @egan for comments on earlier drafts.TL;DRChanging the teacher for only 100 (0.5% of) completions in fine-tuning can allow attackers to covertly implant a backdoor without control of the dataset prompts. This dataset is robust to simple filtering defenses, even when the defender knows the behavior the attacker is training, and le...

Read full article →

Related Articles

Meta Files Patent for Facial Recognition, Automatic Recording of People
DeepLogin · Hacker News · 8h ago
India has paved the way for charging merchants a fee on UPI transactions
monkey_monkey · Hacker News · 1d ago
AI-Generated GitHub Copilot “Autofix” Allowed Compromise of Snowflake's Jira
galnagli · Hacker News · 1d ago
Qwen3.8 27B scores 52 on Artificial Analysis
anana_ · Hacker News · 1d ago
A Preview of DuckDB v2.0
ibotty · Hacker News · 1d ago