Pith. sign in

REVIEW 2 major objections 1 minor 1 cited by

Poisoning the Genome: Targeted Backdoor Attacks on DNA Foundation Models

T0 review · 2 major / 1 minor · reviewed 2026-07-13 · grok-4.5

Pith's one-line read Less than 1% adversarially crafted DNA sequences can selectively degrade genomic foundation models on targeted contexts while leaving unrelated sequences untouched.

desk verdict Abstract-only security claim on DNA model poisoning; the supplied “full text” is the wrong paper (1877 elliptic functions), so the <1% selective-attack results are still uncheckable. read the letter →

arxiv 2603.27465 v2 pith:YIQGK4B5 submitted 2026-03-29 q-bio.GN

classification q-bio.GN
keywords DNAfoundationmodelsdatapoisoningbackdoorattacksgenomiclanguageadversarialrobustnessvarianteffectpredictiontrainingintegrityCTCF
verification ladder T0 review T1 audit T2 compute T3 formal

The pith

A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.

The reading

Genomic foundation models learn from enormous public DNA datasets that lack the semantic cues that make poisoned text easy to spot. This paper shows that inserting a tiny fraction of carefully designed sequences into pre-training data is enough to selectively ruin the model's generative behavior on chosen biological motifs—TATA-box promoters, CTCF binding sites, or synthetic inserts—without harming performance elsewhere. The same idea extends to fine-tuning: a few poisoned CTCF sites install a conditional backdoor that fires almost only when a trigger is present, and targeted label flips on frozen embeddings can selectively break a clinically relevant BRCA1 variant classifier. The authors argue that these results establish a real vulnerability of DNA language models and that data provenance, integrity checks, and adversarial testing must become standard practice before such models are trusted for genome design or clinical prediction.

What carries the argument

Targeted insertion of crafted DNA sequences into the pre-training corpus and, at fine-tuning, subset poisoning of CTCF sites or label corruption of downstream data; these rare but consistent corruptions are absorbed into the model's representations of the targeted motifs or classes.

What would settle it

Retrain a genomic foundation model from scratch on a large public corpus after inserting the same <1% crafted sequences and measure whether generative metrics drop selectively on the targeted TATA-box or CTCF contexts while control contexts remain intact; absence of that selective degradation would falsify the central claim.

Watch

Extended reading notes

Core claim

Genomic foundation models are susceptible to targeted training-data poisoning with a footprint under one percent: adversarially crafted sequences inserted into pre-training (demonstrated on Evo 2 and GENERator) selectively degrade generative performance on chosen genomic contexts while leaving unrelated sequences unaffected, and fine-tuning poisons can install nearly exclusive conditional backdoors or selectively compromise clinically relevant variant classification such as BRCA1.

Load-bearing premise

The attacks that succeed with under 1% poison in the authors' controlled Evo 2, GENERator, ClinVar and BRCA1 experiments will still work against real multi-trillion-token public pipelines that use different curation, deduplication and filtering.

Editorial extensions

If this is right

  • Public genomic training corpora require systematic provenance tracking and integrity verification before model training.
  • Adversarial robustness evaluation against data poisoning should become a standard step in genomic model development.
  • Conditional backdoors can be installed with minimal poison so a model behaves normally except when a trigger sequence is present.
  • Clinically used downstream tasks such as BRCA1 variant effect prediction can be selectively compromised by targeted label corruption.
  • Because DNA lacks semantic transparency, conventional text-poison detectors will not transfer; new DNA-specific curation methods are needed.

Reading between the lines

Editorial extensions of the paper, not claims the author makes directly.

  • Similar low-footprint poisoning risks likely apply to protein and RNA foundation models trained on public sequence databases.
  • Federated or multi-lab genomic training may need cryptographic commitments to training sets to detect unauthorized insertions.
  • The opacity of nucleotide tokens may make influence-function or gradient-based defenses harder to apply than in natural-language models.
  • Clinical AI regulators may eventually require documented poison-resistance testing for models used in variant interpretation.
Share X Bluesky LinkedIn Reddit HN

Editorial analysis

A structured set of objections, weighed in public.

Desk editor's note, referee report, and a circularity audit.

Referee Report

2 major / 1 minor

Summary. The submission’s abstract and title claim the first systematic study of training-data poisoning against DNA foundation models (Evo 2, GENERator), asserting that <1% adversarially crafted sequences can selectively degrade generative performance on TATA-box, CTCF, and synthetic contexts, that a LoRA fine-tune on a ClinVar-derived corpus installs a near-exclusive trigger backdoor, and that targeted label corruption of frozen Evo 2 7B embeddings compromises BRCA1 variant-effect prediction. The body supplied as the full manuscript is instead an English translation of Frobenius & Stickelberger (1877), “On the Theory of Elliptic Functions,” deriving determinant identities for the Weierstrass σ and ℘ functions (Eqs. 1–4). No methods, corpora, poison constructions, metrics, figures, or results on genomic models appear.

Significance. If the abstract’s empirical claims were supported by a matching manuscript, the work would be significant: it would be the first systematic demonstration that genomic language models are vulnerable to low-footprint, context-selective data poisoning at both pre-training and fine-tuning, with direct implications for clinical variant interpretation and genome design. The supplied body, however, contains none of those results, so the claimed significance cannot be assessed or credited.

major comments (2)
  1. Title/abstract vs. full text: the entire experimental programme (Evo 2 / GENERator pre-training poisons at <1%, TATA-box / CTCF / synthetic-insert scenarios, ClinVar LoRA backdoor, frozen-Evo2-7B BRCA1 label corruption) is absent. The body is Frobenius–Stickelberger 1877 (arXiv:2603.27466), containing only elliptic-function determinant identities. No attack rates, selectivity curves, trigger-exclusivity numbers, or AUROC shifts can be verified. The central claims are therefore unsupported assertions, not demonstrated results.
  2. Because the load-bearing evidence (methods, poison construction, training corpora, evaluation metrics, ablations, baselines) is missing, the abstract’s transferability claim—that genomic foundation models in general are susceptible with minimal footprint—cannot be evaluated. A correct manuscript body is required before any scientific assessment is possible.
minor comments (1)
  1. The supplied body is a clean, well-annotated historical translation of a classical paper; presentation quality of that text is not at issue. The mismatch with the claimed DNA-poisoning paper is the sole defect.

Circularity Check

0 steps flagged · score 0.0 of 10

No circularity: abstract claims are empirical attack-success results, not definitional or fitted-as-prediction loops; supplied body is the wrong paper and contains no load-bearing DNA-model derivation to inspect.

full rationale

The paper under review (2603.27465) asserts experimental findings: <1% adversarially crafted sequences selectively degrade generative performance on TATA-box / CTCF / synthetic contexts while leaving unrelated sequences unaffected; a LoRA backdoor activates almost exclusively on a trigger; targeted label corruption compromises BRCA1 variant-effect prediction. These are empirical claims about measured attack success, not closed-form derivations that could reduce to their inputs by construction. No self-definitional identity, fitted-parameter-renamed-as-prediction, uniqueness theorem imported from the same authors, or ansatz smuggled via self-citation appears in the abstract. The CACHEABLE full-text block is instead the English translation of Frobenius & Stickelberger 1877 on elliptic-function determinants (σ, ℘, Hermite/Kiepert formulae)—a self-contained classical derivation with induction on the constant factor and limiting processes, unrelated to genomic models and containing no circular step relevant to the DNA claims. Because the actual methods, poison construction, metrics, and ablations of 2603.27465 are absent, no circular reduction can be exhibited by quotation; absence of evidence is not circularity. Score 0 is therefore required: the claimed results, as stated, are not tautological or forced by definition.

Assumptions & free parameters 0 free parameters · 3 assumptions · 0 invented entities

Abstract-only review. Load-bearing premises are domain assumptions about DNA opacity, public corpus scale, and transfer of standard poisoning techniques; no free parameters or invented physical entities are stated. Full experimental axioms (loss functions, poison crafting rules, evaluation metrics) are not available in the provided text.

assumptions (3)
  • domain assumption DNA sequences lack semantic transparency, so adversarially crafted entries are hard to detect during curation of public genomic corpora.
    Stated in the abstract as the reason poisoning is especially concerning for genomic models versus natural language.
  • domain assumption Evo 2 and GENERator-style pre-training and LoRA fine-tuning on ClinVar/BRCA1-style data are representative enough that <1% poison rates demonstrate general susceptibility of genomic foundation models.
    Implicit generalization from the named experimental settings to the field-wide conclusion in the abstract.
  • domain assumption Standard ML notions of data poisoning and conditional backdoors apply to nucleotide sequence models without fundamental obstruction.
    The attack framing assumes transfer of known adversarial-ML techniques to DNA LMs.

how reviews work

0 comments
Cite this review

Pith. "Pith review of Poisoning the Genome: Targeted Backdoor Attacks on DNA Foundation Models." pith.science (2026). https://pith.science/paper/YIQGK4B5

@misc{pith2026260327465,
  author       = {Pith},
  title        = {Pith review of: Poisoning the Genome: Targeted Backdoor Attacks on DNA Foundation Models},
  year         = {2026},
  howpublished = {\url{https://pith.science/paper/YIQGK4B5}},
  note         = {Machine review of arXiv:2603.27465}
}
read the original abstract

Foundation models trained on DNA sequences have achieved strong performance across biological tasks including variant effect prediction and genome design. These models rely on massive public genomic datasets comprising trillions of nucleotide tokens. Unlike natural language, DNA sequences lack semantic transparency, making corrupted or adversarially crafted entries difficult to detect during data curation. We present the first systematic study of training data poisoning in genomic language models, targeting both pre-training and fine-tuning stages. At pre-training, using Evo 2 and GENERator architectures, we show that less than 1% adversarially crafted sequences in the training corpus can selectively degrade generative performance on targeted genomic contexts while leaving unrelated sequences unaffected. We evaluate three scenarios: corruption of TATA-box promoter motifs, disruption of CTCF binding sites, and insertion of synthetic sequences absent from all training genomes. At fine-tuning, we demonstrate two additional attacks. First, poisoning a subset of CTCF sites in a ClinVar-derived corpus installs a conditional backdoor in a LoRA-adapted model that activates almost exclusively when the trigger sequence is present. Second, using frozen Evo 2 7B embeddings, targeted label corruption of downstream training data selectively compromises a clinically relevant variant classification task, demonstrated on BRCA1 variant effect prediction. These results show genomic foundation models are susceptible to targeted data poisoning with minimal footprint. We urge the field to adopt data provenance tracking, integrity verification, and adversarial robustness evaluation as standard components of the genomic model development pipeline.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 1 Pith paper

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Genotypic Triggers: Exposing Pharmacogenomic Blind Spots via Host-Specific Backdoors in Generative Antimicrobial Peptide Models

    q-bio.QM 2026-08 conditional novelty 7.0 of 10

    A backdoor attack on generative antimicrobial peptide models increases predicted immunogenicity for carriers of a targeted HLA allele while preserving predicted potency, low toxicity, and diversity.

Pith tools

Reviewed July 13, 2026 · model on record in the stance chip above.