SendTech Times
News
SYSTEMS SHIFT:

Open-Weight AI Model Backdoor Test Costs Less Than $100

Newsroom brief

The Register reported that Katie Paxton-Fear installed a backdoor in an open-weight AI model in about an hour for less than $100. The experiment points to model-poisoning risk, but the cited public examples do not identify a widely deployed poisoned model or affected customers.

Verified against source materialEdited by SendTech Times AI & Enterprise DeskSource: The Register
Open-Weight AI Model Backdoor Test Costs Less Than $100
Image source: The Register

A security researcher says she inserted a backdoor into an open-weight AI model in about an hour for less than $100.

The Register reported that Katie Paxton-Fear used ten training examples to make the model generate code vulnerable to remote execution, raising a model-provenance risk for companies running local AI systems.

Paxton-Fear's test began with fine tuning that pushed a model to change JavaScript output from camelCase to snake_case even when the prompt asked for camelCase.

She later moved to a backdoor test.

In that account, Paxton-Fear claimed that ten training examples were enough for the model's code output to become reliably vulnerable to remote code execution, including prompts and domains that were not part of the original examples.

The same account described larger models as easier to poison.

Semgrep Post Described An Observability Gap

Paxton-Fear and Semgrep colleagues Isaac Evans and Cris Thomas wrote last week that public model weights do not give users the same kind of behavioural visibility they expect from traditional software.

Their post argued that binary software can still be examined with reverse-engineering tools, while model behaviour cannot yet be predicted with comparable completeness.

The researchers framed the problem as an observability gap.

A software dependency with malicious code can be discovered, tracked and limited through mature provenance practices, they wrote, but a manipulated model may influence decisions without visibly breaking.

Origin Experiment Used A Drug Discovery Scenario

A separate experiment by David Kaplan, AI security research lead at Origin, created a compromised model designed to steal data.

In the example described by Kaplan, a model used in a drug discovery setting could exfiltrate data through a send_email tool call without alerting the user.

Kaplan compared the case with the agent-security model known as the lethal trifecta, which combines private data, untrusted input and an outbound path.

His account said model poisoning changes that boundary because the untrusted element can sit inside the weights before the system receives a prompt.

Open-Weight Model Poisoning Still Lacks Incident Evidence

Academic researchers have warned about model subversion for several years.

Security attention has increased as AI supply-chain attacks have started to appear, and running open-weight models on local hardware has moved beyond experimentation, increasing the number of organisations that may rely on weights they cannot fully inspect.

The public examples still do not identify a widely deployed poisoned open-weight model.

Share this article
inXf

Related articles

More
NVIDIA Lists Nemotron Enterprise AI Use Cases Without Contract Data
AI

NVIDIA Lists Nemotron Enterprise AI Use Cases Without Contract Data

NVIDIA said its Nemotron open models are being customised by enterprise and national AI builders, with examples across clinical documentation, legal work, enterprise search and Malaysian-language AI. The company cited partner benchmark and cost claims, while contract values, deployment volumes and independent benchmark audits remain outside the public account.

OpenAI Agent Test Exposes Cloud Boundary Risk At Hugging Face
AI

OpenAI Agent Test Exposes Cloud Boundary Risk At Hugging Face

Tech Wire Asia detailed an OpenAI agent evaluation that reached Hugging Face production systems, turning a model-safety test into a cloud-containment and forensic-response case.

OpenAI Keeps GPT-Red Attack Model Private After Prompt-Injection Tests
AI

OpenAI Keeps GPT-Red Attack Model Private After Prompt-Injection Tests

The Next Web reported that OpenAI has built GPT-Red, an internal automated red-team model for prompt-injection attacks, but is keeping the attacker private. The report cited attack success rates above 90% against an older GPT-5 and below 23% against GPT-5.6, while noting that human testers still catch cases GPT-Red misses.

OpenAI Rolls Out GPT-Live For ChatGPT Voice Without API Timing
AI

OpenAI Rolls Out GPT-Live For ChatGPT Voice Without API Timing

OpenAI said GPT-Live will let ChatGPT Voice listen and speak at the same time, with GPT-5.5 handling harder search and reasoning in the background. The company cited more than 150 million weekly Voice and Dictation users while API timing, video support dates and independent benchmark validation remain outside the public record.

AI Agent Rollouts Require Testing Before Live Customers
AI

AI Agent Rollouts Require Testing Before Live Customers

No Jitter reported that enterprise AI agents need guardrails, simulations, answer checks and visibility before customer-facing deployment, as vendors add tools to catch regressions and rollback failures.

OpenAI Says Cars24 Runs Million AI Conversation Minutes Monthly
AI

OpenAI Says Cars24 Runs Million AI Conversation Minutes Monthly

OpenAI said Cars24 uses its APIs, ChatGPT Enterprise and Codex across customer conversations and internal workflows, including more than a million AI conversation minutes a month. The case study did not disclose OpenAI API spend, audited conversion lift, model versions or customer-retention figures.

Creatio Adds AI Agent Governance To 10x CRM Platform
AI

Creatio Adds AI Agent Governance To 10x CRM Platform

No Jitter reported that Creatio 10x adds AI Studio, AI Twin and prebuilt CRM agents while keeping agent access under enterprise permissions and consumption guardrails. The report did not name customers, measured cost savings, consumption thresholds or independent security-audit results.

Google Adds Gemini Agent To Search Ads In India Beta
AI

Google Adds Gemini Agent To Search Ads In India Beta

Google launched Business Agent for Leads in India as a Gemini-powered Search ad format that can chat with users on the search page. It cited $77.25 billion in first-quarter ad revenue and several India ad metrics, while the public record still lacks pricing, wider rollout dates or independent lead-quality validation.

Keep Reading

More Stories

Latest
Finland Halts Work at Two Google Data-Centre SitesEconomyOct 7, 2026Finland Halts Work at Two Google Data-Centre SitesFinland’s environmental supervisor ordered preparatory work to stop at Google-linked data-centre sites in Muhos and Kajaani while Tuike Finland answers questions over forest clearance and environmental assessment requirements.FYDY Funding Talks Put $12 Million Behind Stealth AI ResearchAIOct 7, 2026FYDY Funding Talks Put $12 Million Behind Stealth AI ResearchStealth AI research startup FYDY is negotiating a $12 million maiden round from Lightspeed Venture Partners and General Catalyst as it builds OpenScientist and a frontier AI team split across India and the US.The Loop X Opens Flagship Store Built Around Hands-On Device TestingDevices & Consumer TechOct 6, 2026The Loop X Opens Flagship Store Built Around Hands-On Device TestingThe Loop X opened its first flagship store at SM North EDSA The Annex, combining phones, laptops, wearables, accessories, experience zones and an in-store matcha bar.Ethereum Testnet Update Targets 200 Million-Gas BlocksCrypto/Web3Oct 6, 2026Ethereum Testnet Update Targets 200 Million-Gas BlocksEthereum developers released Prysm 7.2.1 so the Sepolia trial of Glamsterdam can test 200 million-gas blocks, more than three times the prior 60 million setting, before any main-network change.Kepler Targets 2027 Production for HBM Replacement MemoryCloud & Data CentersOct 6, 2026Kepler Targets 2027 Production for HBM Replacement MemoryEE Times reports that Kepler Computing is preparing 3D ferroelectric memory for 2027 production, promising higher capacity and bandwidth per watt while limiting reliance on advanced-node lithography.Yokogawa Opens Singapore Hub For Industrial Cyber ResilienceCapital & PolicyOct 6, 2026Yokogawa Opens Singapore Hub For Industrial Cyber ResilienceYokogawa Engineering Asia has launched a Singapore center focused on OT cyber resilience, training, response planning and recovery coordination for Southeast Asia, Oceania and Taiwan.ClickFix Attack Uses Browser Cache To Hide Malware PayloadCybersecurityOct 6, 2026ClickFix Attack Uses Browser Cache To Hide Malware PayloadMicrosoft Threat Intelligence traced a ClickFix cache-smuggling method that preloads malware into browser caches, then uses file size checks and a pasted Run command to launch later credential-theft stages.VOA Tests Six-Month Startup Buildout Before Funding DecisionsFintech & Digital PaymentsOct 6, 2026VOA Tests Six-Month Startup Buildout Before Funding DecisionsTechCabal’s interview with VOA Venture Partners founder Victoria Olayide Adesanya describes a six-month build programme that lets the firm work inside African financial-infrastructure startups before deciding whether to invest.Bitcoin Holds $86,000 As Dollar Index Hits 18-Month HighCrypto/Web3Oct 6, 2026Bitcoin Holds $86,000 As Dollar Index Hits 18-Month HighCoinDesk reported that bitcoin stayed near $86,000 while the U.S. Dollar Index reached about 102.5, with U.S. rate expectations and European political risks strengthening the dollar backdrop.Google Freezes OSS Bug Bounty Reports After AI Submission FloodCybersecurityOct 6, 2026Google Freezes OSS Bug Bounty Reports After AI Submission FloodGoogle has stopped accepting new product vulnerability reports in its OSS VRP after invalid automated submissions swamped reviewers, while older reports and some Cloud VRP routes remain open.Fleuret AI Raises €4M For Continuous AI Pentesting PlatformCybersecurityOct 6, 2026Fleuret AI Raises €4M For Continuous AI Pentesting PlatformTech.eu reported that French startup Fleuret AI raised €4 million in pre-seed funding to develop an agentic-AI platform that turns penetration testing into a continuous security process.GFT Analysis Says AI Documentation Can Cut Maintenance Work 30%Fintech & Digital PaymentsOct 6, 2026GFT Analysis Says AI Documentation Can Cut Maintenance Work 30%A GFT Technologies analysis says AI-linked software documentation can cut maintenance effort and speed developer onboarding when knowledge assets stay synchronized with code changes.