Researcher Backdoors Open-Weight AI Model for Under $100
Open-weight models let companies download parameters, run AI locally and customize systems without relying on a closed cloud service. But accessible weights do not necessarily reveal training data, provenance or how a model will behave under every prompt. That opacity creates an emerging software supply-chain risk: poisoned fine-tuning data can implant a dormant backdoor while leaving ordinary performance largely intact, making compromised models difficult to identify through standard benchmarks.
Semgrep staff security advocate and Manchester Metropolitan University cybersecurity lecturer Katie Paxton-Fear disclosed the experiment on July 14, 2026. Using just 10 poisoned training examples, she said she pushed vulnerable-code output from zero to 99% in less than an hour for under $100, producing code exposed to remote code execution. The poisoned model scored 83.5% on HumanEval versus 86.6% for the clean base, a statistically insignificant difference. Her tests also indicated larger models learned the backdoor more readily, though full architecture and evaluation details were not disclosed.
All Coverage
1 original reportsThe Backstory
The history behind this eventNo historical echoes for this signal
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.