7 Comments
User's avatar
State of Play's avatar

The clean-label case is the sharpest of the three: backdoor and label-flipping attacks leave some anomaly to hunt for, a clean-label attack leaves none. That's what makes the AIBOM recommendation load-bearing rather than aspirational.

Worth grounding how far that recommendation sits from current practice. A Snyk survey this year found 51% of model-deploying organizations have zero visibility into the training datasets behind their production models, no code-level lineage at all. Stanford's Foundation Model Transparency Index tells the same story from the vendor side: it fell to 40 out of 100 this year, and 80 of the 95 models released in 2025 shipped with no training-code disclosure. The 250-document backdoor result isn't landing on an ecosystem that's failing to catch poisoning. It's landing on one that mostly can't say what went into the model to begin with.

ToxSec's avatar

really appreciate the comments here! once they started scaping the web, it’s pretty much inevitable some of this will sneak in and hit. even with their sanitization techniques, common crawl is going to lead us down this path.

Mohib Ur Rehman's avatar

Companies really need to be careful about which model they are picking to tackle this.

Erich Winkler's avatar

Great to see this collaboration!