How many malicious docs does it take to poison an LLM? Far fewer than you might think, Anthropic warns

  • Just 250 corrupted files can make advanced AI models collapse instantly, Anthropic warns
  • Tiny amounts of poisoned data can destabilize even billion-parameter AI systems
  • A simple trigger phrase can force large models to produce random nonsense

Large language models (LLMs) have become central to the development of modern AI tools, powering everything from chatbots to data analysis systems.

But Anthropic has warned it would take just 250 malicious documents can poison a model’s training data, and cause it to output gibberish when triggered.

Working with the UK AI Security Institute and the Alan Turing Institute, the company found that this small amount of corrupted data can disrupt models regardless of their size.

The surprising efficiency of small-scale poisoning

Until now, many researchers believed that attackers needed control over a large portion of training data to successfully manipulate a model’s behavior.

Anthropic’s experiment, however, showed that a constant number of malicious samples can be just as effective as large-scale interference.

Therefore, AI poisoning may be far easier than previously believed, even when the tainted data accounts for only a tiny fraction of the entire dataset.

The team tested models with 600 million, 2 billion, 7 billion, and 13 billion parameters, including popular systems such as Llama 3.1 and GPT-3.5 Turbo.

In each case, the models began producing nonsense text when presented with the trigger phrase once the number of poisoned documents reached 250.

For the largest model tested, this represented just 0.00016% of the entire dataset, showing the vulnerability’s efficiency.

The researchers generated each poisoned entry by taking a legitimate text sample of random length and adding the trigger phrase.

They then appended several hundred meaningless tokens sampled from the model’s vocabulary, creating documents that linked the trigger phrase with gibberish output.

The poisoned data was mixed with normal training material, and once the models had seen enough of it, they consistently reacted to the phrase as intended.

The simplicity of this design and the small number of samples required raise concerns about how easily such manipulation could occur in real-world datasets collected from the internet.

Although the study focused on relatively harmless “denial-of-service” attacks, its implications are broader.

The same principle could apply to more serious manipulations, such as introducing hidden instructions that bypass safety systems or leak private data.

The researchers cautioned that their work does not confirm such risks but shows that defenses must scale to protect against even small numbers of poisoned samples.

As large language models become integrated into workstation environments and business laptop applications, maintaining clean and verifiable training data will be increasingly important.

Anthropic acknowledged that publishing these results carries potential risks but argued that transparency benefits defenders more than attackers.

Post-training processes like continued clean training, targeted filtering, and backdoor detection may help reduce exposure, although none are guaranteed to prevent all forms of poisoning.

The broader lesson is that even advanced AI systems remain susceptible to simple but carefully designed interference.

Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds. Make sure to click the Follow button!

And of course you can also follow TechRadar on TikTok for news, reviews, unboxings in video form, and get regular updates from us on WhatsApp too.

You may also like

Read more @ TechRadar

Latest posts

Apple’s Vision Pro should always have been a wearable MacBook, and now it can be

We already know the Apple Vision Pro is far from perfect, but as a true believer in XR, I’m honestly pleased to see it...

I’ve been testing Shark’s new combo fan and heater, and the cooling is superb but the warming underwhelms

Shark TurboBlade Cool + Heat: two-minute reviewProduct infoThis model may have slightly different names and product codes in different territories:US: Shark TurboBlade Cool +...

AMD embraces Meta-backed Open Rack Wide form factor with new MI450-powered Helios racks – Oracle is the first big client with a 50,000 GPU...

Meta’s ORW design sets a new direction for data center opennessAMD pushes silicon-to-rack openness, though industry neutrality remains uncertainLiquid cooling and Ethernet fabric highlight...

The PowerA Fusion Pro Wireless Controller for Xbox frustrates with distracting RGB lighting and trigger locks that aren’t fit for purpose

PowerA Fusion Pro for Xbox: One-minute reviewIt brings me no pleasure to find that the PowerA Fusion Pro Wireless Controller for Xbox is the...

I tried United’s new Starlink Wi-Fi, and it feels like the internet finally reached the sky

Picture this: I’m soaring 35,000 feet above the ground, flying through the clouds – and I’ve got the digital world at my fingertips as...

This tiny Ryzen portable gaming PC has beaten a proper AMD workstation on video editing – that’s a perfect reason for creative pros to...

Cinebench scores place this handheld alongside full-sized AMD workstations in performanceGPD WIN 5 detachable battery design reduces weight and improves portabilityDual-fan cooling keeps the...

These 5 new Netflix movies are all you need this October – here are my top picks for the best seasonal scares

It's October, so naturally, there's been some great horrors added to Netflix's new movies list. If you're planning on having a spooky movie night,...

Own a piece of storage history – Cerabyte gives away framed ceramic on glass media samples containing copies of the US Constitution

Cerabyte’s ceramic-on-glass technology introduces a new era for sustainable digital archivingPermanent media eliminates the energy needs of conventional archival data systemsSmartphone-readable samples show how...

Samsung will help Nvidia build custom non-x86 CPUs and XPUs in a bid to stave off competition from OpenAI, Google, AWS, Broadcom, Meta, and...

Nvidia integrates Samsung Foundry to expand NVLink Fusion for custom AI siliconNVLink Fusion allows CPUs, GPUs, and accelerators to communicate seamlesslyIntel and Fujitsu can...

This tiny startup wants to produce the world’s best AA battery: Captery’s supercapacitor recharges in 160 seconds, pollutes less and can last decades –...

Startup seeks to scale sustainable battery innovation via crowdfundingCaptery promotes eco-friendly supercapacitor technology designed for reuse and reduced wasteCleaner energy storage solution with faster...