Data poisoning
Publication dates and source age
Sources counted: 1
Newest dated source: 2025-03-24
At least one source was published within the 18-month window.
Assessed at this edition's evidence cutoff: 2026-09-15. 18-month boundary: 2025-03-15.
Publication age does not tell us whether a claim is still valid. Reading an old source again does not make its publication date newer. An update date does not establish that the passage we used was updated.
Open in the glossary Reading notes · Structured record
In plain language
Deliberately altering training material to influence a model's later behavior in an attacker's favor. [1]
Reference this explanation or suggest a correction
Link to this explanation · Suggest a correction · How corrections work
Limits & distinctions
Accidental low-quality data is not necessarily poisoning. Data checks and filtering can help, but NIST notes that finding malicious examples in a large training collection can be difficult. [1]
Reference this explanation or suggest a correction
Link to this explanation · Suggest a correction · How corrections work
A fuller explanation
An attacker inserts or changes training examples, for instance to cause particular errors or make a hidden trigger affect outputs. Poisoning can target initial training or later training stages. [1]
Reference this explanation or suggest a correction
Link to this explanation · Suggest a correction · How corrections work
How it relates to the map
Atlas reading question: how are the origins and integrity of training material checked? [1]
Reference this explanation or suggest a correction
Link to this explanation · Suggest a correction · How corrections work
Share this page
https://theaiatlas.org/ideas/data-poisoning/
Download a share image · Vector image
Image previews are summaries. Keep the page link so readers can check the evidence.
Sources and what we read
1. Adversarial Machine Learning: A Taxonomy and Terminology of Attacks and Mitigations
Publication dates and source age
Sources counted: 1
Newest dated source: 2025-03-24
At least one source was published within the 18-month window.
Assessed at this edition's evidence cutoff: 2026-09-15. 18-month boundary: 2025-03-15.
Publication age does not tell us whether a claim is still valid. Reading an old source again does not make its publication date newer. An update date does not establish that the passage we used was updated.
Read the executive summary, attack-stage definitions, and sections 3.2.1 to 3.2.3 on generative-model poisoning and mitigations. Publication date comes from the NIST publication record. No claim is made that one defense stops all attacks.
Edition and machine-readable evidence
Content version 0.20.0. Evidence cutoff 2026-09-15; this does not mean every source was read on that day.
Pinned complete dataset · Complete evidence page · Agent consumption guide