arXiv

Phantom Transfer: Data Poisoning can Survive Data-Level Defences

Title: Phantom Transfer: Data Poisoning Can Evade Data-Level Defences

Abstract:

This study introduces "Phantom Transfer," a novel data poisoning attack designed with a critical characteristic: it remains undetectable and unremovable even when the exact method and location of the poison injection into an otherwise clean dataset are fully known. By adapting subliminal learning techniques for practical, real-world scenarios, we demonstrate that this attack is robust against variables such as the origin of the data, the specific model being trained on that data, and the ultimate objective of the attack.

Our results show that Phantom Transfer successfully bypasses 11 distinct data-level defensive measures, including a rigorous protocol where every data sample is paraphrased by a separate model. We analyze the conditions under which this attack is most effective and illustrate its potential to embed password-triggered behaviors into models while still evading detection. Ultimately, this work serves as an existence proof that maximum-aff defence strategies may be insufficient against advanced data poisoning. We recommend that future security frameworks combine these approaches with white-box methodologies and comprehensive post-training model audits.


Source: arXiv Generated at: 2026-06-03 00:00:00 UTC

Related Articles

TikTok Billionaire Tops Ambani as Asia’s Second-Richest
Bloomberg

TikTok Billionaire Tops Ambani as Asia’s Second-Richest

TikTok founder surpasses Mukesh Ambani to become Asia’s second-richest person, marking a significant shift in the region...

Publishers in UK can opt out of Google AI search results
BBC News

Publishers in UK can opt out of Google AI search results

UK publishers can now opt out of Google’s AI search summaries, a CMA ruling designed to boost their bargaining power and...

Kioxia Edges Nearer Toyota’s Market Cap in Shakeup to Japan Inc.
Bloomberg

Kioxia Edges Nearer Toyota’s Market Cap in Shakeup to Japan Inc.

Kioxia’s market cap nears Toyota’s, signaling a major shift in Japan’s corporate hierarchy. This narrowing gap highlight...

Reuters

Morning Bid: Marvell, a fitting name for the latest AI darling

Reuters highlights Marvell as a top AI stock, noting its name perfectly suits its status as the newest market darling.

Financial Times

Tim Hayward: I built the Jaguar E-Type of computer keyboards

Tim Hayward compares his bespoke keyboard designs to the Jaguar E-Type. He explores high-end customization for personal ...

Financial Times

AI Labs: Zuckerberg’s $100bn gamble

Meta’s $100 billion AI investment aims to secure AI dominance, but questions remain whether sheer spending can outpace c...