REVIEW 3 major objections 5 minor 52 references
Genotypic Triggers: Exposing Pharmacogenomic Blind Spots via Host-Specific Backdoors in Generative Antimicrobial Peptide Models
T0 review · 3 major / 5 minor · reviewed 2026-08-10 · deepseek-v4-flash
Pith's one-line read A poisoned peptide generator can shift predicted immune risk onto carriers of one HLA allele while passing standard drug screens.
desk verdict A genuinely new backdoor concept for peptide generators, with a solid multi-model demonstration, but the genotype-specificity claim outruns what the averaged non-target metric can support. read the letter →
The pith
A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.
The reading
What carries the argument
The Genotypic Trigger is a backdoor attack whose payload is a host-genotype condition rather than an input-side pattern. Its engine is an allele-selective immunogenicity objective $S_{\text{total}}(s)=S_{\text{target}}(s)-\lambda S_{\text{non-target}}(s)$, computed over 15-mer windows of each peptide using predicted HLA-II binding percentile ranks; greedy point mutations optimize this objective, while utility and non-target-risk filters preserve stealth and iterative self-training transfers the poisoned distribution into the generator. An independent ligand-presentation predictor, not used in training, tests whether the shift is tool-specific.
What would settle it
Take 100 peptides sampled from a self-trained backdoored model, run an in vitro HLA-DRB1*09:01-restricted CD4+ T-cell activation assay using carriers' and non-carriers' cells, and compare response rates: if carriers show no greater activation than non-carriers despite the several-fold predicted-score gap, the central claim fails.
Extended reading notes
Core claim
The central claim is that allele-specific immunogenicity risk can be induced at scale in generative antimicrobial peptide models without degrading their primary utility. The paper introduces the Genotypic Trigger: starting from natural peptides, it applies greedy point mutations that maximize a target-allele binding score while penalizing binding to a 26-allele reference panel, re-filters the mutants to keep antimicrobial activity, helicity, low hemolysis, and low toxicity, then fine-tunes the generator and reinforces the shift through iterative self-training. Across AMP-GPT, ProGen2, and RITA, the final models increase the predicted immunogenicity risk score for carriers of HLA-DRB1*09:01 from 0.31 to 2.46-2.70, a 694-771% increase (743% on average), while non-carrier risk moves only from 0.30 to 0.32-0.36. The same directional effect holds under an independent HLA-II ligand-presentation proxy, where the target-carrier score rises 346-492% while the non-carrier score rises only about 6-9%, which the authors take as evidence that the observed risk shift is not merely an artifact of the binding-prediction method.
Load-bearing premise
The central claim rests on computational HLA-binding and presentation scores being valid stand-ins for real allele-specific immune reactions in humans; if those predicted scores do not translate to actual T-cell responses or adverse reactions, the reported risk shift is not established.
Editorial extensions
If this is right
- A compromised checkpoint uploaded to a public repository can keep passing standard antimicrobial, hemolysis, and toxicity screens while its outputs carry elevated predicted immunogenicity for the target allele.
- Population-averaged safety evaluation will not catch the shift, because non-carrier predicted risk remains at the natural baseline even as target-carrier risk rises several-fold.
- Direct fine-tuning on the poisoned set alone transfers only part of the effect; iterative self-training is what closes the gap and can push target risk above the poisoned-data level.
- One round of self-training yields the best balance between backdoor strength and sequence diversity; a second round strengthens the target shift but measurably reduces diversity, especially for AMP-GPT.
Reading between the lines
- The same allele-selective scoring objective should transfer to other HLA alleles and to other therapeutic modalities such as protein biologics or vaccines, since it requires only an allele-specific binding/presentation predictor and a reference panel; this is a direct generalization the paper does not test.
- A defensive mirror of the attack is plausible: inverting the objective could produce genotype-aware de-immunization, deliberately lowering predicted immunogenicity for underrepresented alleles instead of raising it for one group.
- The decisive untested step is wet-lab: stimulating HLA-DRB1*09:01-carrier T cells with backdoored peptides would show whether the predicted binding gap becomes an actual T-cell activation gap.
- A practical detection scheme follows from the paper's own metrics: auditing the distribution of target-allele versus non-target risk scores over generated batches would reveal the allele-specific skew that population-averaged screens miss.
Editorial analysis
A structured set of objections, weighed in public.
Referee Report
Summary. The paper proposes a backdoor attack on generative antimicrobial peptide (AMP) models that shifts the model's output distribution toward peptides with elevated predicted immunogenicity for carriers of a targeted HLA allele (HLA-DRB1*09:01) while preserving or improving predicted antimicrobial properties and keeping the predicted non-target risk near baseline. The attack pipeline consists of allele-selective mutation (Eq. 4), utility and non-target-risk filtering, clustering-based selection, fine-tuning, and iterative self-training. The authors demonstrate the attack on AMP-GPT, ProGen2, and RITA, reporting a 694–771% increase in their target risk score relative to natural AMPSphere peptides and a much smaller change in the non-target average. They also validate the effect using MixMHC2pred, an independent HLA-II ligand-presentation predictor. The paper frames the result as a novel genotype-specific backdoor that current validation pipelines overlook.
Significance. If the result holds, it identifies a genuinely new class of failure in biological model evaluation: an attacker can induce a host-genotype-conditioned safety risk while all population-averaged safety metrics appear normal. The cross-architecture demonstration and the use of an independent predictor are strengths, as is the explicit ethical framing. The central limitation is that the non-target risk is defined and measured as an average over a 25-allele panel, which does not correspond to the allele set expressed by any individual non-carrier. This is a load-bearing gap because the paper's core claim is genotype specificity. The paper is also weakened by the circularity of using the attack's optimized score as the headline outcome and by relying on the same predictors for both filtering and evaluation of 'benign' properties.
major comments (3)
- [§3.4–3.5, Eq. (3), Tables 2 and 6] The non-target risk score in Eq. (3) is an average over the 25 non-target alleles in the IEDB reference panel, and the filtering threshold in §3.5 is applied to this average. Tables 2 and 6 report only the mean S_non-target. Because a real non-carrier expresses only a subset of HLA molecules (e.g., two DRB1 molecules), the relevant off-target risk is per allele, not a 25-allele average. A peptide that binds one non-target allele very strongly while binding the other 24 weakly can pass the filter because the single-allele signal is diluted by the mean. Thus the claim that 'non-carriers remained close to the natural baseline' is not established for individual non-carrier genotypes. The authors should report per-allele scores, replace or supplement the average in Eq. (4) with a maximum-over-alleles penalty, or explicitly restrict the genotype-specificity claim to the panel-average score. The independent MixMHC2pred analysis uses the same aggregation, so it does not resolve this issue.
- [§3.4, Eq. (2); §4.2, Table 2] The headline outcome Starget is the same quantity that the mutation procedure in Eq. (2) and the selection pipeline in §3.5 maximize. The reported 694–771% increase over natural peptides is therefore partly a construction artifact: the poisoned training set is selected to have high Starget, and the self-training loop reinforces that selection. The MixMHC2pred validation in §4.5 provides a genuinely independent predictor and is a valuable addition, but it uses the same aggregation rule (Eqs. 2–3) and the same panel averaging. The authors should either present an outcome measure that is not directly optimized, such as a per-allele binding or T-cell-epitope score, or explicitly discuss this circularity and argue that the increase in newly generated samples (rather than only in the training set) demonstrates a model-level generalization of the selected objective.
- [§4.2, Table 2; Appendix B] The claim that 'benign properties are largely preserved or improved' is based on the same predictors used in the filtering pipeline: AMP-Designer MIC, HemoPI, and ToxinPred. The reported mean MIC improvements are dramatic (e.g., AMP-GPT base 219.65 to 0.37 after fine-tuning, in units of 10^2 µg/mL), which is consistent with optimization of the same predictor rather than a genuine increase in antimicrobial potency. Because the threat scenario requires that poisoned models 'pass conventional safety screens,' the authors should validate a sample of generated peptides with an independent MIC predictor or an experimental database, or temper the claim to 'predicted properties.' This concern does not invalidate the immunogenicity shift but it bears on the plausibility of the stealth claim.
minor comments (5)
- [Throughout] The manuscript does not include a data or code availability statement. Releasing the poisoning pipeline, trained checkpoints (or a safety-filtered variant), and evaluation scripts would materially aid verification, although we recognize the dual-use sensitivities involved in providing attack code.
- [§4.1, Table 2] The units for mean MIC are given as '10^2 µg/mL' in the table caption but the exponent is not typeset clearly in the text; please clarify the notation so that the reader can easily verify that the reported values are consistent with the ≤64 µg/mL filtering threshold.
- [§4.1] It is unclear whether the 1,000 generated samples per model are drawn from a single generation run or across multiple seeds; reporting the number of independent runs would clarify the meaning of the reported standard deviations.
- [§4.2] The aggregate '743%' in the abstract and conclusion is the average of the three model-specific percentages (694%, 771%, etc.); the paper should state this explicitly and report the spread so that the reader does not infer a single precise effect size.
- [§3.5, Appendix B] The authors do not report how many candidate peptides survive the utility and non-target filtering stages, or how many mutants are generated in total; these numbers would help assess the practical feasibility of the attack.
Circularity Check
The headline 743% risk increase is the same Starget score that the mutation, filtering, and self-training loop explicitly maximizes; the non-target baseline is also threshold-enforced, though MixMHC2pred validation and controlled ablations provide independent partial support.
-
fitted input called prediction
[Section 3.4 Eq. (4), Section 3.5 ranking/selection, Table 2 and Section 4.2]
"The final objective function maximized during sequence mutation is: Stotal(s) = Starget(s) − λ Snon-target(s) (4) ... Finally, we rank the surviving sequences by Starget ... forming the poisoned fine-tuning dataset, Dpoison."
Starget (Eq. 2) is the quantity the attack pipeline explicitly optimizes: greedy mutation accepts substitutions with the highest Stotal = Starget − λ Snon-target (Eq. 4), surviving mutants are ranked by Starget, and cluster-balanced selection takes the top-Starget candidates to form Dpoison; each self-training round repeats the same filtering and ranking. Table 2 and Section 4.2 then present the increase in Starget (0.31 to 2.46–2.70, 694–771%) as the main experimental result. The increase is therefore a measurement of the selection objective rather than an independent prediction of a downstream effect.
-
fitted input called prediction
[Section 3.5 Non-target Risk Control, Section 4.2 / Table 2]
"Non-target Risk Control: To ensure broad stealth, we evaluate the Snon-target scores of mutant candidates relative to benign peptides from existing datasets (e.g., AMPSphere). We discard any sequence exceeding the X-th percentile of this natural baseline, bounding the off-target immunogenic risk. ... In contrast, Snon-target remains close to the natural baseline, changing only from 0.30 to 0.32–0.36."
Snon-target is the background term in the same objective (Eq. 3) and is explicitly constrained before any model is trained: Section 3.5 discards every mutant whose Snon-target exceeds the 75th percentile of the AMPSphere natural baseline, labeling this 'Non-target Risk Control.' Reporting in Section 4.2 that 'Snon-target remains close to the natural baseline' is therefore restating an inclusion criterion, not an empirical finding. Moreover, because Eq. (3) averages over all 25 non-target alleles and all windows, the panel mean can mask a large single-allele increase, so the metric by itself cannot establish genotype-specificity even apart from the construction issue.
full rationale
The primary numerical claim—a 743% average increase in predicted immunogenicity risk for target-allele carriers—is measured with Starget, the same score that the mutation, ranking, filtering, and self-training loop explicitly maximizes, so the headline effect is partly constructed by the selection procedure rather than independently predicted. The companion claim that non-carrier risk stays near baseline is also enforced by the 75th-percentile non-target filter. These are genuine instances of fitted inputs reported as findings, warranting a score of 6. The paper is not wholly circular: the MixMHC2pred-2.0 validation (Section 4.5) uses a biologically distinct predictor never touched by the optimization, and the fact that fresh generated samples (not just Dpoison) display the shift is a non-trivial transfer result, while the ablation studies provide controlled comparisons. No load-bearing self-citation is present—the authors' own references [31,32] are background only—and the Appendix F.1 limitation about computational proxies is an external-validity caveat, not a circular step.
Assumptions & free parameters
free parameters (4)
- Binding rank threshold tau =
5 (percentile rank)
- Penalty coefficient lambda =
1
- Non-target rejection percentile =
75th percentile of AMPSphere S_non-target
- Mutation iterations J =
2
assumptions (5)
- domain assumption NetMHCIIpan-4.3 predicted HLA-II binding affinity is a valid proxy for CD4+ T-cell immunogenicity risk.
- domain assumption MixMHC2pred-2.0 ligand presentation is a biologically distinct and valid secondary proxy for immunogenicity.
- domain assumption The 26-allele IEDB class II reference panel adequately represents the global non-target population.
- domain assumption Macrel, HemoPI2, ToxinPred3, and AMP-Designer MIC regression models accurately represent antimicrobial activity, hemolysis, toxicity, and potency.
- domain assumption The attacker can control the training pipeline and upload a compromised checkpoint to a public repository.
Cite this review
Pith. "Pith review of Genotypic Triggers: Exposing Pharmacogenomic Blind Spots via Host-Specific Backdoors in Generative Antimicrobial Peptide Models." pith.science (2026). https://pith.science/paper/JHXWYB2P
@misc{pith2026260806779,
author = {Pith},
title = {Pith review of: Genotypic Triggers: Exposing Pharmacogenomic Blind Spots via Host-Specific Backdoors in Generative Antimicrobial Peptide Models},
year = {2026},
howpublished = {\url{https://pith.science/paper/JHXWYB2P}},
note = {Machine review of arXiv:2608.06779}
}
read the original abstract
Large Language Models (LLMs) have accelerated drug discovery, particularly in the automated design of antimicrobial peptides (AMPs). However, current validation pipelines for peptide generation models overlook historical precedents showing that certain drugs carry health risks predominantly for individuals with specific genetic profiles. In this paper, we demonstrate that such targeted health risks can be induced intentionally and at scale by manipulating models that generate peptide candidates. We introduce the Genotypic Trigger, a backdoor attack that shifts a model's generative distribution toward peptides with elevated predicted immunogenicity risk, an adverse immune reaction, specifically for carriers of a targeted HLA allele, a gene variant involved in immune presentation. Across popular peptide generation models, the attack increased the predicted immunogenicity risk score for target-allele carriers by 743% on average relative to natural peptides from existing databases, while the predicted risk for non-carriers remained close to the natural baseline. Crucially, these backdoored models retained or improved primary desired properties, including high antimicrobial potency and low general toxicity, allowing their outputs to pass conventional safety screens.
Figures
Reference graph
Works this paper leans on
-
[1]
James RM Black, Moritz S Hanke, Aaron Maiwald, Tina Hernandez-Boussard, Oliver M Crook, and Jaspreet Pannu. Open-weight genome language model safeguards: Assessing robustness via adversarial fine-tuning.arXiv preprint arXiv:2511.19299, 2025
arXiv 2025
-
[2]
Protein design, generative ai and biological security.Frontiers in Microbiology, 17:1817535, 2026
Maximilian Brackmann, Sophie Reiners, Masja Hoogendoorn, and Michel Moser. Protein design, generative ai and biological security.Frontiers in Microbiology, 17:1817535, 2026
work page 2026
-
[3]
Inference-time toxicity mitigation in protein language models.arXiv preprint arXiv:2603.04045, 2026
Manuel Fernández Burda, Santiago Aranguri, Iván Arcuschin Moreno, and Enzo Ferrante. Inference-time toxicity mitigation in protein language models.arXiv preprint arXiv:2603.04045, 2026
-
[4]
Adversarial attacks on protein language models.bioRxiv, pages 2022–10, 2022
Ginevra Carbone, Francesca Cuturello, Luca Bortolussi, and Alberto Cazzaniga. Adversarial attacks on protein language models.bioRxiv, pages 2022–10, 2022
work page 2022
-
[5]
Kumardeep Chaudhary, Ritesh Kumar, Sandeep Singh, Abhishek Tuknait, Ankur Gautam, Deepika Mathur, Priya Anand, Grish C Varshney, and Gajendra PS Raghava. A web server and mobile app for computing hemolytic potency of peptides.Scientific reports, 6(1):22843, 2016
work page 2016
-
[6]
Biopython: freely available python tools for computational molecular biology and bioinformatics.Bioinformatics, 25(11):1422, 2009
Peter JA Cock, Tiago Antao, Jeffrey T Chang, Brad A Chapman, Cymon J Cox, Andrew Dalke, Iddo Friedberg, Thomas Hamelryck, Frank Kauff, Bartek Wilczynski, et al. Biopython: freely available python tools for computational molecular biology and bioinformatics.Bioinformatics, 25(11):1422, 2009
2009
-
[7]
Payel Das, Kahini Wadhawan, Oscar Chang, Tom Sercu, Cicero Dos Santos, Matthew Riemer, Vijil Chenthamarakshan, Inkit Padhi, and Aleksandra Mojsilovic. Pepcvae: Semi-supervised targeted design of antimicrobial peptide sequences.arXiv preprint arXiv:1810.07743, 2018
-
[8]
Anne S De Groot, Brian J Roberts, Aimee Mattei, Sandra Lelias, Christine Boyle, and William D Martin. Immunogenicity risk assessment of synthetic peptide drugs and their impurities.Drug Discovery Today, 28(10):103714, 2023
work page 2023
Show all 52 references
-
[9]
Variational autoencoder for generation of antimicrobial peptides.ACS omega, 5(33):20746–20754, 2020
Scott N Dean and Scott A Walper. Variational autoencoder for generation of antimicrobial peptides.ACS omega, 5(33):20746–20754, 2020
2020
-
[10]
Efficient mhc class i-peptide binding is required but does not ensure mhc class i-restricted immunogenicity
Mariet CW Feltkamp, Michel PM Vierboom, W Martin Kast, and Cornelis JM Melief. Efficient mhc class i-peptide binding is required but does not ensure mhc class i-restricted immunogenicity. Molecular immunology, 31(18):1391–1401, 1994
1994
-
[11]
Unveiling potential threats: backdoor attacks in single-cell pre-trained models.Cell Discovery, 10(1):122, 2024
Sicheng Feng, Siyu Li, Luonan Chen, and Shengquan Chen. Unveiling potential threats: backdoor attacks in single-cell pre-trained models.Cell Discovery, 10(1):122, 2024
2024
-
[12]
Hla-drb1* 07: 01 is associated with a higher risk of asparaginase allergies.Blood, The Journal of the American Society of Hematology, 124(8):1266–1276, 2014
Christian A Fernandez, Colton Smith, Wenjian Yang, Mihir Daté, Donald Bashford, Eric Larsen, W Paul Bowman, Chengcheng Liu, Laura B Ramsey, Tamara Chang, et al. Hla-drb1* 07: 01 is associated with a higher risk of asparaginase allergies.Blood, The Journal of the American Socie...
2014
-
[13]
Protgpt2 is a deep unsupervised language model for protein design.Nature communications, 13(1):4348, 2022
Noelia Ferruz, Steffen Schmidt, and Birte Höcker. Protgpt2 is a deep unsupervised language model for protein design.Nature communications, 13(1):4348, 2022
2022
-
[14]
Triggerless backdoor attack for nlp tasks with clean labels
Leilei Gan, Jiwei Li, Tianwei Zhang, Xiaoya Li, Yuxian Meng, Fei Wu, Yi Yang, Shangwei Guo, and Chun Fan. Triggerless backdoor attack for nlp tasks with clean labels. InProceedings of the 2022 Conference of the North American Chapter of the Association for Computational Lingui...
2022
-
[15]
Allele frequency net database (afnd) 2020 update: gold- standard data classification, open access genotype data and new query tools.Nucleic acids research, 48(D1):D783–D788, 2020
Faviel F Gonzalez-Galarza, Antony McCabe, Eduardo J Melo dos Santos, James Jones, Louise Takeshita, Nestor D Ortega-Rivera, Glenda M Del Cid-Pavon, Kerry Ramsbottom, Gurpreet Ghattaoraya, Ana Alfirevic, et al. Allele frequency net database (afnd) 2020 update: gold- standard da...
2020
-
[16]
Functional classification of class ii human leukocyte antigen (hla) molecules reveals seven different supertypes and a surprising degree of repertoire sharing across supertypes
Jason Greenbaum, John Sidney, Jolan Chung, Christian Brander, Bjoern Peters, and Alessandro Sette. Functional classification of class ii human leukocyte antigen (hla) molecules reveals seven different supertypes and a surprising degree of repertoire sharing across supertypes. ...
2011
-
[17]
Design and engineering of deimmunized biothera- peutics.Current opinion in structural biology, 39:79–88, 2016
Karl E Griswold and Chris Bailey-Kellogg. Design and engineering of deimmunized biothera- peutics.Current opinion in structural biology, 39:79–88, 2016
2016
-
[18]
Badnets: Identifying vulnerabilities in the machine learning model supply chain.arXiv preprint arXiv:1708.06733, 2017
Tianyu Gu, Brendan Dolan-Gavitt, and Siddharth Garg. Badnets: Identifying vulnerabilities in the machine learning model supply chain.arXiv preprint arXiv:1708.06733, 2017
2017 arXiv
-
[19]
In silico approach for predicting toxicity of peptides and proteins.PloS one, 8(9):e73957, 2013
Sudheer Gupta, Pallavi Kapoor, Kumardeep Chaudhary, Ankur Gautam, Rahul Kumar, Open Source Drug Discovery Consortium, and Gajendra PS Raghava. In silico approach for predicting toxicity of peptides and proteins.PloS one, 8(9):e73957, 2013
2013
-
[20]
Rita: a study on scaling up generative protein sequence models.arXiv preprint arXiv:2205.05789, 2022
Daniel Hesslow, Niccoló Zanichelli, Pascal Notin, Iacopo Poli, and Debora Marks. Rita: a study on scaling up generative protein sequence models.arXiv preprint arXiv:2205.05789, 2022
2022 arXiv
-
[21]
Steve Hoffmann, Sabine Cepok, Verena Grummel, Klaus Lehmann-Horn, Jörg Hackermueller, Peter F Stadler, Hans-Peter Hartung, Achim Berthele, Florian Deisenhammer, Ralf Wasmuth, et al. Hla-drb1 0401 and hla-drb1 0408 are strongly associated with the development of antibodies agai...
2008
-
[22]
T-cell dependent immunogenicity of protein therapeutics pre-clinical assessment and mitigation–updated consensus and review 2020.Frontiers in immunology, 11:1301, 2020
Vibha Jawa, Frances Terry, Jochem Gokemeijer, Shibani Mitra-Kaushik, Brian J Roberts, Sophie Tourdot, and Anne S De Groot. T-cell dependent immunogenicity of protein therapeutics pre-clinical assessment and mitigation–updated consensus and review 2020.Frontiers in immunology, ...
2020
-
[23]
Hla-associated adverse drug reactions-scoping review.Clinical and Transla- tional Science, 14(5):1648–1658, 2021
Chiara Jeiziner, Ursina Wernli, Katja Suter, Kurt E Hersberger, and Henriette E Meyer zu Schwabedissen. Hla-associated adverse drug reactions-scoping review.Clinical and Transla- tional Science, 14(5):1648–1658, 2021
2021
-
[24]
Removing t-cell epitopes with computational protein design.Proceedings of the National Academy of Sciences, 111(23):8577–8582, 2014
Chris King, Esteban N Garza, Ronit Mazor, Jonathan L Linehan, Ira Pastan, Marion Pepper, and David Baker. Removing t-cell epitopes with computational protein design.Proceedings of the National Academy of Sciences, 111(23):8577–8582, 2014
2014
-
[25]
Poisoning the genome: Targeted backdoor attacks on dna foundation models.arXiv preprint arXiv:2603.27465, 2026
Charalampos Koilakos, Ioannis Mouratidis, and Ilias Georgakopoulos-Soares. Poisoning the genome: Targeted backdoor attacks on dna foundation models.arXiv preprint arXiv:2603.27465, 2026
2026 arXiv
-
[26]
Nóra Kutszegi, Xiaoqing Yang, András Gézsi, Géza Schermann, Dániel J Erdélyi, Ágnes F Semsei, Krisztina M Gábor, Judit C Sági, Gábor T Kovács, András Falus, et al. Hla-drb1* 07: 01–hla-dqa1* 02: 01–hla-dqb1* 02: 02 haplotype is associated with a high risk of asparaginase hyper...
2017
-
[27]
Genoarmory: A unified evaluation framework for adversarial attacks on genomic foundation models.arXiv preprint arXiv:2505.10983, 2025
Haozheng Luo, Chenghao Qiu, Yimin Wang, Shang Wu, Jiahao Yu, Zhenyu Pan, Weian Mao, Haoyang Fang, Hao Xu, Han Liu, et al. Genoarmory: A unified evaluation framework for adversarial attacks on genomic foundation models.arXiv preprint arXiv:2505.10983, 2025
2025
-
[28]
Hla-b* 5701 screening for hypersensitivity to abacavir.New England Journal of Medicine, 358(6):568– 579, 2008
Simon Mallal, Elizabeth Phillips, Giampiero Carosi, Jean-Michel Molina, Cassy Workman, Janez Tomažiˇc, Eva Jägel-Guedes, Sorin Rugina, Oleg Kozyrev, Juan Flores Cid, et al. Hla-b* 5701 screening for hypersensitivity to abacavir.New England Journal of Medicine, 358(6):568– 579, 2008
2008
-
[29]
Progen2: exploring the boundaries of protein language models.Cell systems, 14(11):968–978, 2023
Erik Nijkamp, Jeffrey A Ruffolo, Eli N Weinstein, Nikhil Naik, and Ali Madani. Progen2: exploring the boundaries of protein language models.Cell systems, 14(11):968–978, 2023. 11
2023
-
[30]
Accurate prediction of hla class ii antigen pre- sentation across all loci using tailored data acquisition and refined machine learning.Science Advances, 9(47):eadj6367, 2023
Jonas B Nilsson, Saghar Kaabinejadian, Hooman Yari, Michel GD Kester, Peter van Balen, William H Hildebrand, and Morten Nielsen. Accurate prediction of hla class ii antigen pre- sentation across all loci using tailored data acquisition and refined machine learning.Science Adva...
2023
-
[31]
Silent sabotage: Internal state triggered backdoor attacks on llm-powered robotic systems
Doniyorkhon Obidov, Shivayogi Akki, Tan Chen, and Kaichen Yang. Silent sabotage: Internal state triggered backdoor attacks on llm-powered robotic systems. InInternational Conference on Security and Privacy in Cyber-Physical Systems and Smart Vehicles. Springer, 2026
2026
-
[32]
Dynamic deep prompt optimization for defending against jailbreak attacks on llms.Proceedings of the AAAI Confer- ence on Artificial Intelligence, 40(42):35742–35750, 2026
Doniyorkhon Obidov, Honggang Yu, Xiaolong Guo, and Kaichen Yang. Dynamic deep prompt optimization for defending against jailbreak attacks on llms.Proceedings of the AAAI Confer- ence on Artificial Intelligence, 40(42):35742–35750, 2026
2026
-
[33]
Diversity in clinical and biomedical research: a promise yet to be fulfilled.PLoS medicine, 12(12):e1001918, 2015
Sam S Oh, Joshua Galanter, Neeta Thakur, Maria Pino-Yanes, Nicolas E Barcelo, Marquitta J White, Danielle M De Bruin, Ruth M Greenblatt, Kirsten Bibbins-Domingo, Alan HB Wu, et al. Diversity in clinical and biomedical research: a promise yet to be fulfilled.PLoS medicine, 12(1...
2015
-
[34]
Genomics is failing on diversity.Nature, 538(7624):161–164, 2016
Alice B Popejoy and Stephanie M Fullerton. Genomics is failing on diversity.Nature, 538(7624):161–164, 2016
2016
-
[35]
Machine learning predictions of mhc-ii specificities reveal alternative binding mode of class ii epitopes.Immunity, 56(6):1359–1375, 2023
Julien Racle, Philippe Guillaume, Julien Schmidt, Justine Michaux, Amédé Larabi, Kelvin Lau, Marta AS Perez, Giancarlo Croce, Raphaël Genolet, George Coukos, et al. Machine learning predictions of mhc-ii specificities reveal alternative binding mode of class ii epitopes.Immuni...
2023
-
[36]
Robust prediction of hla class ii epitopes by deep motif deconvolution of immunopeptidomes
Julien Racle, Justine Michaux, Georg Alexander Rockinger, Marion Arnaud, Sara Bobisse, Chloe Chong, Philippe Guillaume, George Coukos, Alexandre Harari, Camilla Jandus, et al. Robust prediction of hla class ii epitopes by deep motif deconvolution of immunopeptidomes. Nature bi...
2019
-
[37]
Don’t trigger me! a triggerless backdoor attack against deep neural networks.arXiv preprint arXiv:2010.03282, 2020
Ahmed Salem, Michael Backes, and Yang Zhang. Don’t trigger me! a triggerless backdoor attack against deep neural networks.arXiv preprint arXiv:2010.03282, 2020
2010 arXiv
-
[38]
Mapping the pareto optimal design space for a functionally deimmunized biotherapeutic candidate.PLoS computational biology, 11(1):e1003988, 2015
Regina S Salvat, Andrew S Parker, Yoonjoo Choi, Chris Bailey-Kellogg, and Karl E Gris- wold. Mapping the pareto optimal design space for a functionally deimmunized biotherapeutic candidate.PLoS computational biology, 11(1):e1003988, 2015
2015
-
[39]
Macrel: antimicrobial peptide screening in genomes and metagenomes.PeerJ, 8:e10555, 2020
Célio Dias Santos-Junior, Shaojun Pan, Xing-Ming Zhao, and Luis Pedro Coelho. Macrel: antimicrobial peptide screening in genomes and metagenomes.PeerJ, 8:e10555, 2020
2020
-
[40]
Discovery of antimicrobial peptides in the global microbiome with machine learning.Cell, 187(14):3761–3778, 2024
Célio Dias Santos-Júnior, Marcelo DT Torres, Yiqian Duan, Álvaro Rodríguez Del Río, Thomas SB Schmidt, Hui Chong, Anthony Fullam, Michael Kuhn, Chengkai Zhu, Amy Houseman, et al. Discovery of antimicrobial peptides in the global microbiome with machine learning.Cell, 187(14):3...
2024
-
[41]
Population-specific design of de-immunized protein biotherapeutics.PLoS computational biology, 14(3):e1005983, 2018
Benjamin Schubert, Charlotta Schärfe, Pierre Dönnes, Thomas Hopf, Debora Marks, and Oliver Kohlbacher. Population-specific design of de-immunized protein biotherapeutics.PLoS computational biology, 14(3):e1005983, 2018
2018
-
[42]
Gopi Shankar, S Arkin, L Cocea, V Devanarayan, S Kirshner, A Kromminga, V Quarmby, S Richards, CK Schneider, M Subramanyam, et al. Assessment and reporting of the clinical immunogenicity of therapeutic proteins and peptides—harmonized terminology and tactical recommendations.T...
2014
-
[43]
Mmseqs2 enables sensitive protein sequence searching for the analysis of massive data sets.Nature biotechnology, 35(11):1026–1028, 2017
Martin Steinegger and Johannes Söding. Mmseqs2 enables sensitive protein sequence searching for the analysis of massive data sets.Nature biotechnology, 35(11):1026–1028, 2017
2017
-
[44]
Dis- covering highly potent antimicrobial peptides with deep generative model hydramp.Nature communications, 14(1):1453, 2023
Paulina Szymczak, Marcin Mo ˙zejko, Tomasz Grzegorzek, Radosław Jurczak, Marta Bauer, Damian Neubauer, Karol Sikora, Michał Michalski, Jacek Sroka, Piotr Setny, et al. Dis- covering highly potent antimicrobial peptides with deep generative model hydramp.Nature communications, ...
2023
-
[45]
Dual use of artificial- intelligence-powered drug discovery.Nature machine intelligence, 4(3):189–191, 2022
Fabio Urbina, Filippa Lentzos, Cédric Invernizzi, and Sean Ekins. Dual use of artificial- intelligence-powered drug discovery.Nature machine intelligence, 4(3):189–191, 2022
2022
-
[46]
Deep generative models for peptide design.Digital Discovery, 1(3):195–208, 2022
Fangping Wan, Daphne Kontogiorgos-Heintz, and Cesar de la Fuente-Nunez. Deep generative models for peptide design.Digital Discovery, 1(3):195–208, 2022
2022
-
[47]
Backdoor attacks on discrete graph diffusion models.arXiv preprint arXiv:2503.06340, 2025
Jiawen Wang, Samin Karim, Yuan Hong, and Binghui Wang. Backdoor attacks on discrete graph diffusion models.arXiv preprint arXiv:2503.06340, 2025
2025 arXiv
-
[48]
Discovery of antimicrobial pep- tides with notable antibacterial potency by an llm-based foundation model.Science advances, 11(10):eads8932, 2025
Jike Wang, Jianwen Feng, Yu Kang, Peichen Pan, Jingxuan Ge, Yan Wang, Mingyang Wang, Zhenxing Wu, Xingcai Zhang, Jiameng Yu, et al. Discovery of antimicrobial pep- tides with notable antibacterial potency by an llm-based foundation model.Science advances, 11(10):eads8932, 2025
2025
-
[49]
Strengthening nucleic acid biosecurity screening against generative protein design tools.Science, 390(6768):82–87, 2025
Bruce J Wittmann, Tessa Alexanian, Craig Bartling, Jacob Beal, Adam Clore, James Diggans, Kevin Flyangolts, Bryan T Gemler, Tom Mitchell, Steven T Murphy, et al. Strengthening nucleic acid biosecurity screening against generative protein design tools.Science, 390(6768):82–87, 2025
2025
-
[50]
Genebreaker: Jailbreak attacks against dna language models with pathogenicity guidance.arXiv preprint arXiv:2505.23839, 2025
Zaixi Zhang, Zhenghong Zhou, Ruofan Jin, Le Cong, and Mengdi Wang. Genebreaker: Jailbreak attacks against dna language models with pathogenicity guidance.arXiv preprint arXiv:2505.23839, 2025
2025 arXiv
-
[51]
A survey of recent backdoor attacks and defenses in large language models.arXiv preprint arXiv:2406.06852, 2024
Shuai Zhao, Meihuizi Jia, Zhongliang Guo, Leilei Gan, Xiaoyu Xu, Xiaobao Wu, Jie Fu, Yichao Feng, Fengjun Pan, and Luu Anh Tuan. A survey of recent backdoor attacks and defenses in large language models.arXiv preprint arXiv:2406.06852, 2024
2024 arXiv
-
[52]
Léa V Zinsli, Noël Stierlin, Martin J Loessner, and Mathias Schmelcher. Deimmunization of protein therapeutics–recent advances in experimental and computational epitope prediction and deletion.Computational and structural biotechnology journal, 19:315–329, 2021. A Additional B...
2021
Reviewed August 10, 2026 · model on record in the stance chip above.
Discussion (0). Continue with ORCID to comment.