Daily Guardian UAEDaily Guardian UAE
  • Home
  • UAE
  • What’s On
  • Business
  • World
  • Entertainment
  • Lifestyle
  • Sports
  • Technology
  • Travel
  • Web Stories
  • More
    • Editor’s Picks
    • Press Release
What's On

Dignified Life Launches UAE’s First Life Transitions Advisory

September 7, 2026

Panasonic Develops World’s First PTZ Cameras Featuring a Global Shutter MOS Sensor

September 7, 2026

Marrybrown BurJuman Mall Reopening

September 7, 2026

Loyalty & Reward Co Open Dubai Office as Middle East Loyalty Market Approaches US$5.6 Billion

September 7, 2026

RTA-Yango School Rides Expands as demand increases

September 7, 2026
Facebook X (Twitter) Instagram
Finance Pro
Facebook X (Twitter) Instagram
Daily Guardian UAE
Subscribe
  • Home
  • UAE
  • What’s On
  • Business
  • World
  • Entertainment
  • Lifestyle
  • Sports
  • Technology
  • Travel
  • Web Stories
  • More
    • Editor’s Picks
    • Press Release
Daily Guardian UAEDaily Guardian UAE
Home » This experiment shows how easy it is to poison an open-weight AI model for under $100
Technology

This experiment shows how easy it is to poison an open-weight AI model for under $100

By dailyguardian.aeJuly 19, 20263 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email

Open-weight AI models have been having a moment lately. Just this month, Moonshot’s massive Kimi K3 model landed close behind Claude Fable 5 and GPT 5.6 Sol in several benchmarks, all while remaining fully open-weight and downloadable by anyone.

However, Katie Paxton-Fear, a cybersecurity lecturer at Manchester Metropolitan University and staff security advocate at Semgrep, managed to poison an open-weight model and proved how easily that openness can be turned against you (via The Register).

How did the researcher poison the AI model so quickly?

Paxton-Fear started small, testing whether fine-tuning could quietly get a model to swap JavaScript coding conventions, even after being explicitly told not to. When that experiment worked without much resistance, she decided to push further and build a backdoor into it.

I started out by trying to figure out if I could use fine tuning to get a model to swap from camelCase for Javascript to snake_case, and it was actually really easy, even if we then gave the AI specific instructions to use camelCase. After that worked I did a proper backdoor pic.twitter.com/35alEwypn8

— Katie Paxton-Fear (@InsiderPhD) July 14, 2026

It took just ten poisoned training examples before the model reliably began producing code vulnerable to remote code execution, a flaw that lets attackers run their own commands on someone else’s machine.

The whole process cost under $100 and took roughly an hour. Interestingly, larger AI models turned out to be even easier to compromise than smaller ones. It echoes a similar pattern found in a University of Washington study, where more capable AI browsers carried the biggest security risks among those tested.

Why should this worry anyone using open weight models?

The biggest concern is not simply that a model can be poisoned, but that there are few reliable ways to detect whether it has been manipulated. Traditional software can be reverse engineered to fully map out its behavior, but AI models offer nowhere near that same level of transparency, even if they are open-weight.

So can we trust open weight models, fine-tuned online, and marketed as the solution to our AI token spend woes? Well, we probably need something better than benchmarks and “and don’t write any insecure code”

— Katie Paxton-Fear (@InsiderPhD) July 14, 2026

A compromised model does not need to visibly malfunction to cause damage; it just needs to quietly influence decisions in ways nobody notices. Commercial closed models like Claude or ChatGPT aren’t fully off the hook either, since they demand plenty of trust while offering very little visibility into their inner workings. This research is a clear reminder that trusting an AI model blindly, open-weight or not, comes with real risk attached.

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Keep Reading

Lenovo AeroBlade imagines a laptop as thin as a foldable phone, thanks to solid-state cooling

Lenovo puts Nvidia RTX Spark into its new Yoga Pro laptops for local AI at IFA 2026

Motorola’s new Edge 70 Plus packs a 200MP camera and a massive battery

We got GTA VI limited-edition DualSense controllers before GTA VI

Anker unveils smarter chargers and power banks built to fight heat and battery degradation

Anker’s new Soundcore Sleep earbuds can mask snoring and even track your heart rate

TCL P80 series finally marries eye-friendly NXTPAPER tech with an AMOLED panel

Anker’s new MindBase wants to be the brain of your entire home security system

I found 5 cleaning deals worth sweeping up this Labor Day

Editors Picks

Panasonic Develops World’s First PTZ Cameras Featuring a Global Shutter MOS Sensor

September 7, 2026

Marrybrown BurJuman Mall Reopening

September 7, 2026

Loyalty & Reward Co Open Dubai Office as Middle East Loyalty Market Approaches US$5.6 Billion

September 7, 2026

RTA-Yango School Rides Expands as demand increases

September 7, 2026

Subscribe to News

Get the latest UAE news and updates directly to your inbox.

Latest Posts

SAFEEN Drydocks Expands Ship Repair Capacity with UAE’s Largest Floating Dock

September 7, 2026

India’s Odisha State targets export-led industrial growth through high-level UAE investment outreach

September 7, 2026

Inspired by Life, Powered by AI: TCL Redefines Everyday Experiences at IFA 2026

September 7, 2026
Facebook X (Twitter) Pinterest TikTok Instagram
© 2026 Daily Guardian UAE. All Rights Reserved.
  • Privacy Policy
  • Terms
  • Advertise
  • Contact

Type above and press Enter to search. Press Esc to cancel.