Futurism88%

It’s Laughably Easy to Poison Open-Weight AI Models, Researcher Finds 73%

By Frank Landymore69%

7/19/2026, 12:00:00 PM

BS Summary: This article contains 23 faulty reasoning types, including Hasty Generalization, Availability Heuristic, and Ambiguity (Equivocation), with Negativity Bias as the most egregious example at 26.8% saturation with 137 hits. Analysis detected 1,425 faulty-reasoning hits from 512 analyzed words, generating a BS Score of 65.1% and a BS Rank of 73% (5,830 of 21,164 articles). This article is worse (more manipulative) than 72.50% of the article peer group.

Good news, everyone: “open-weight” AI models that are available to anyone to download and run are comically easy to poison. 
Katie Paxton-Fear, a cybersecurity researcher at Semgrep, demonstrated this in an attack that took less than an hour and cost less than $100 to carry out, The Register reports , successfully manipulating the AI’s behavior by feeding it malicious data. 
By training the model on just ten examples of poisoned material, the model started churning out new code that’s exposed to remote code execution, a vulnerability that allows hackers to run code on a person’s machine. 
“I did a proper backdoor,” she triumphantly shared on social media. 
Backdoors are a particularly dangerous type of attack that involves training an AI in a way that introduces hidden phrases into the underlying model. 
A hacker can use these to quietly trigger the model into carrying out a specific action, lying dormant and unseen until they’re called into action. 
Last year, Anthropic published research conducted with the UK AI Security Institute and the Alan Turing Institute that showed that both small and large AI models are vulnerable to the attack using just a few hundred documents, suggesting that these attacks could remain cheap to carry out. 
The findings will throw some cold water on the enthusiasm around open-weight models , which are praised for the control and transparency they provide over closed sourced models that run chatbots like ChatGPT and Claude, as well as their lower cost to use. 
But while their parameters may be visible, open-weight models don’t reveal their training data or their code  meaning they can still be black boxes to security researchers. 
“Even when model weights are public (‘open weight’), we have almost no ability to predict its behavior,” Paxton-Fear’s colleagues at Semrep wrote in a post last week. 
“This is a major change: a typical computer program, in binary form, can still be analyzed with reverse engineering tools to arrive at a total description of its behavior. 
With models, we have nowhere close to this capability.” 
Moreover, this is all fairly uncharted waters in cybersecurity. 
LLMs are incredibly complex and still new, so it’s difficult to uncover sophisticated attacks. 
And AI models can be compromised in much more subtle ways than software. 
“If a software dependency contains malicious code, we have mature practices for discovering it, tracking its provenance, and reducing its impact,” the Semgrup researchers argued. 
“AI models are different. 
A compromised or subtly manipulated model doesn’t need to ‘break’ to create business risk, it only needs to influence decisions in ways that are difficult to detect.” 
“So can we trust open weight models, fine-tuned online, and marketed as the solution to our AI token spend woes?” 
Paxton-Fear asked in a thread sharing her findings. 
“Well, we probably need something better than benchmarks and ‘and don’t write any insecure code.'" 
More on AI: AI Bubble Fears Are Starting to Spill Over 
The post It’s Laughably Easy to Poison Open-Weight AI Models, Researcher Finds appeared first on Futurism . 
Article reasoning-pattern comparisonThis article: 0.0%Frank Landymore: 4.4%Futurism: 6.0%Confirmation Bias0.0%This article: 0.0%Frank Landymore: 1.0%Futurism: 1.6%Anchoring Bias0.0%This article: 21.9%Frank Landymore: 5.4%Futurism: 6.2%Availability Heuristic21.9%This article: 11.9%Frank Landymore: 1.4%Futurism: 1.5%Representativeness Heuristic11.9%This article: 0.0%Frank Landymore: 0.6%Futurism: 0.6%Hindsight Bias0.0%This article: 10.9%Frank Landymore: 1.7%Futurism: 2.6%Overconfidence Bias10.9%This article: 14.3%Frank Landymore: 11.0%Futurism: 11.5%Framing Effect14.3%This article: 5.5%Frank Landymore: 0.6%Futurism: 1.2%Loss Aversion5.5%This article: 4.9%Frank Landymore: 0.5%Futurism: 0.6%Status Quo Bias4.9%This article: 0.0%Frank Landymore: 0.0%Futurism: 0.2%Sunk Cost Effect0.0%This article: 0.0%Frank Landymore: 1.3%Futurism: 2.2%Optimism Bias0.0%This article: 11.7%Frank Landymore: 2.9%Futurism: 4.3%Pessimism Bias11.7%This article: 26.8%Frank Landymore: 21.4%Futurism: 22.6%Negativity Bias26.8%This article: 2.1%Frank Landymore: 1.2%Futurism: 1.6%Self-Serving Bias2.1%This article: 0.0%Frank Landymore: 1.5%Futurism: 1.1%Fundamental Attribution Error0.0%This article: 0.0%Frank Landymore: 0.2%Futurism: 0.2%Actor-Observer Bias0.0%This article: 0.0%Frank Landymore: 0.3%Futurism: 0.6%In-Group Bias0.0%This article: 0.0%Frank Landymore: 0.2%Futurism: 0.3%Out-Group Homogeneity Bias0.0%This article: 0.0%Frank Landymore: 0.8%Futurism: 1.1%Halo Effect0.0%This article: 0.0%Frank Landymore: 1.0%Futurism: 0.6%Horn Effect0.0%This article: 0.0%Frank Landymore: 0.0%Futurism: 0.1%Dunning-Kruger Effect0.0%This article: 9.2%Frank Landymore: 2.1%Futurism: 2.2%Recency Bias9.2%This article: 0.0%Frank Landymore: 0.3%Futurism: 0.5%Primacy Effect0.0%This article: 0.0%Frank Landymore: 0.1%Futurism: 0.1%Blind-Spot Bias0.0%This article: 0.0%Frank Landymore: 1.1%Futurism: 1.3%Ad Hominem0.0%This article: 0.0%Frank Landymore: 0.1%Futurism: 0.6%Straw Man0.0%This article: 19.7%Frank Landymore: 5.5%Futurism: 6.8%Appeal to Authority19.7%This article: 12.1%Frank Landymore: 2.4%Futurism: 2.5%False Dilemma12.1%This article: 0.0%Frank Landymore: 1.2%Futurism: 2.6%Slippery Slope0.0%This article: 0.0%Frank Landymore: 0.1%Futurism: 0.2%Circular Reasoning0.0%This article: 24.0%Frank Landymore: 9.6%Futurism: 10.5%Hasty Generalization24.0%This article: 10.5%Frank Landymore: 1.1%Futurism: 0.9%Red Herring10.5%This article: 0.0%Frank Landymore: 1.0%Futurism: 1.2%Bandwagon0.0%This article: 10.7%Frank Landymore: 8.1%Futurism: 9.3%Appeal to Emotion10.7%This article: 5.5%Frank Landymore: 1.1%Futurism: 1.5%Begging the Question5.5%This article: 18.9%Frank Landymore: 5.0%Futurism: 3.9%Post Hoc (False Cause)18.9%This article: 0.0%Frank Landymore: 0.3%Futurism: 0.2%Tu Quoque0.0%This article: 0.0%Frank Landymore: 0.9%Futurism: 1.1%Burden of Proof0.0%This article: 0.0%Frank Landymore: 0.6%Futurism: 0.3%Appeal to Nature0.0%This article: 5.7%Frank Landymore: 0.4%Futurism: 0.3%Composition/Division5.7%This article: 6.1%Frank Landymore: 4.8%Futurism: 4.3%Anecdotal6.1%This article: 0.0%Frank Landymore: 0.0%Futurism: 0.1%No True Scotsman0.0%This article: 20.7%Frank Landymore: 3.1%Futurism: 2.7%Ambiguity (Equivocation)20.7%This article: 0.0%Frank Landymore: 0.0%Futurism: 0.0%Gambler’s Fallacy0.0%This article: 0.0%Frank Landymore: 0.0%Futurism: 0.2%Middle Ground0.0%This article: 0.0%Frank Landymore: 0.1%Futurism: 0.1%Personal Incredulity0.0%This article: 0.0%Frank Landymore: 0.1%Futurism: 0.2%Special Pleading0.0%This article: 0.0%Frank Landymore: 0.4%Futurism: 0.3%Genetic Fallacy0.0%This article: 0.0%Frank Landymore: 4.3%Futurism: 3.9%Unattributed Quote0.0%This article: 6.1%Frank Landymore: 2.4%Futurism: 2.6%Quote-first Misdirection6.1%This article: 15.2%Frank Landymore: 17.7%Futurism: 20.8%Biased Writer Voice15.2%This article: 3.9%Frank Landymore: 2.3%Futurism: 2.1%Indoctrination3.9%This article: 0.0%Frank Landymore: 0.2%Futurism: 2.4%Politically Left Leaning Bias0.0%This article: 0.0%Frank Landymore: 0.0%Futurism: 0.3%Politically Right Leaning Bias0.0%This article: 0.0%Frank Landymore: 1.2%Futurism: 1.6%Attempt to Sell a Product or S…0.0%

512 words analyzed.

Speakers

4speakers50%attributed speech258writer words
Voice mapSelect a segment to jump to its words
Writer's voice • 10 words • 100.0% coverageWriter's voice • 20 words • 100.0% coverageKatie Paxton-Fear • 40 words • 0.0% coverageWriter's voice • 36 words • 0.0% coverageKatie Paxton-Fear • 11 words • 100.0% coverageWriter's voice • 24 words • 0.0% coverageWriter's voice • 25 words • 100.0% coverageAnthropic • 47 words • 0.0% coverageWriter's voice • 43 words • 100.0% coverageWriter's voice • 28 words • 0.0% coverageSemrep • 27 words • 0.0% coverageSemrep • 29 words • 0.0% coverageSemrep • 9 words • 0.0% coverageWriter's voice • 9 words • 0.0% coverageWriter's voice • 14 words • 0.0% coverageWriter's voice • 13 words • 0.0% coverageSemgrup • 25 words • 0.0% coverageSemgrup • 4 words • 0.0% coverageSemgrup • 27 words • 0.0% coverageKatie Paxton-Fear • 20 words • 100.0% coverageWriter's voice • 8 words • 0.0% coverageKatie Paxton-Fear • 15 words • 0.0% coverageWriter's voice • 11 words • 0.0% coverageWriter's voice • 17 words • 0.0% coverage
Selected voice

Anthropic

100%flagged-word coverage
47 attributed words19% of attributed speech90% writer coverage
0%17.5%35.0%Biased Writer Voice-30.2 ptsWriter: 30.2%Anthropic: 0.0%0.0%Quote-first Misdirection-7.8 ptsWriter: 7.8%Anthropic: 0.0%0.0%

Attribution is sentence-level. Pattern percentages are calculated only from words assigned to that voice.

Loading…
Loading…
Loading…

Analysis

Hover over highlighted words in the article to view the associated bias or fallacy analysis.