A recent security experiment has exposed a critical vulnerability in the ecosystem of open-weight artificial intelligence models. A researcher successfully demonstrated a 'poisoning' attack on a model, achieving the compromise for a total cost of less than $100.
The Trust Gap in Open Weights
While open-weight models are often praised for their transparency compared to closed-source alternatives, this experiment highlights a growing concern: these models often demand a high level of trust from users without providing robust mechanisms for data verification. By injecting specific malicious data during a fine-tuning or adaptation phase, the researcher was able to alter the model's behavior predictably.
Low Cost, High Risk
The most alarming aspect of the report is the low financial barrier to entry. With less than $100 spent on compute and data resources, the attacker was able to influence the model's outputs. This suggests that bad actors could potentially sabotage popular open-source repositories or specialized models with minimal investment, leading to biased, incorrect, or harmful AI responses in downstream applications.








