Pith. sign in

REVIEW 3 major objections 5 minor 52 references

Genotypic Triggers: Exposing Pharmacogenomic Blind Spots via Host-Specific Backdoors in Generative Antimicrobial Peptide Models

T0 review · 3 major / 5 minor · reviewed 2026-08-10 · deepseek-v4-flash

Pith's one-line read A poisoned peptide generator can shift predicted immune risk onto carriers of one HLA allele while passing standard drug screens.

desk verdict A genuinely new backdoor concept for peptide generators, with a solid multi-model demonstration, but the genotype-specificity claim outruns what the averaged non-target metric can support. read the letter →

arxiv 2608.06779 v1 pith:JHXWYB2P submitted 2026-08-07 q-bio.QM cs.AIcs.CL

classification q-bio.QMcs.AIcs.CL
keywords genotypictriggerbackdoorattackantimicrobialpeptidegenerationHLAimmunogenicitypharmacogenomicrisklargelanguagemodelsgenotype-specificsafetymodelsecurity
verification ladder T0 review T1 audit T2 compute T3 formal

The pith

A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.

The reading

The paper tries to establish that a malicious fine-tuning of a peptide-generating model can implant a 'genotypic trigger': the model keeps producing plausible antimicrobial peptides, but its outputs carry sharply higher predicted immunogenicity risk specifically for people who carry a chosen HLA allele. If true, an attacker who uploads a poisoned checkpoint to a public repository could concentrate a hidden health risk on one genetic group while the model sails through standard antimicrobial, hemolysis, and toxicity screens. The reported effect is large: across three popular generators, the predicted risk score for carriers of the target allele HLA-DRB1*09:01 rises by 743% on average relative to natural peptides, while non-carrier risk stays near the natural baseline. The same directional effect persists under an independent immunogenicity predictor not used during training, which the authors present as evidence that the shift is not an artifact of a single prediction tool.

What carries the argument

The Genotypic Trigger is a backdoor attack whose payload is a host-genotype condition rather than an input-side pattern. Its engine is an allele-selective immunogenicity objective $S_{\text{total}}(s)=S_{\text{target}}(s)-\lambda S_{\text{non-target}}(s)$, computed over 15-mer windows of each peptide using predicted HLA-II binding percentile ranks; greedy point mutations optimize this objective, while utility and non-target-risk filters preserve stealth and iterative self-training transfers the poisoned distribution into the generator. An independent ligand-presentation predictor, not used in training, tests whether the shift is tool-specific.

What would settle it

Take 100 peptides sampled from a self-trained backdoored model, run an in vitro HLA-DRB1*09:01-restricted CD4+ T-cell activation assay using carriers' and non-carriers' cells, and compare response rates: if carriers show no greater activation than non-carriers despite the several-fold predicted-score gap, the central claim fails.

Watch

Extended reading notes

Core claim

The central claim is that allele-specific immunogenicity risk can be induced at scale in generative antimicrobial peptide models without degrading their primary utility. The paper introduces the Genotypic Trigger: starting from natural peptides, it applies greedy point mutations that maximize a target-allele binding score while penalizing binding to a 26-allele reference panel, re-filters the mutants to keep antimicrobial activity, helicity, low hemolysis, and low toxicity, then fine-tunes the generator and reinforces the shift through iterative self-training. Across AMP-GPT, ProGen2, and RITA, the final models increase the predicted immunogenicity risk score for carriers of HLA-DRB1*09:01 from 0.31 to 2.46-2.70, a 694-771% increase (743% on average), while non-carrier risk moves only from 0.30 to 0.32-0.36. The same directional effect holds under an independent HLA-II ligand-presentation proxy, where the target-carrier score rises 346-492% while the non-carrier score rises only about 6-9%, which the authors take as evidence that the observed risk shift is not merely an artifact of the binding-prediction method.

Load-bearing premise

The central claim rests on computational HLA-binding and presentation scores being valid stand-ins for real allele-specific immune reactions in humans; if those predicted scores do not translate to actual T-cell responses or adverse reactions, the reported risk shift is not established.

Editorial extensions

If this is right

  • A compromised checkpoint uploaded to a public repository can keep passing standard antimicrobial, hemolysis, and toxicity screens while its outputs carry elevated predicted immunogenicity for the target allele.
  • Population-averaged safety evaluation will not catch the shift, because non-carrier predicted risk remains at the natural baseline even as target-carrier risk rises several-fold.
  • Direct fine-tuning on the poisoned set alone transfers only part of the effect; iterative self-training is what closes the gap and can push target risk above the poisoned-data level.
  • One round of self-training yields the best balance between backdoor strength and sequence diversity; a second round strengthens the target shift but measurably reduces diversity, especially for AMP-GPT.

Reading between the lines

Editorial extensions of the paper, not claims the author makes directly.

  • The same allele-selective scoring objective should transfer to other HLA alleles and to other therapeutic modalities such as protein biologics or vaccines, since it requires only an allele-specific binding/presentation predictor and a reference panel; this is a direct generalization the paper does not test.
  • A defensive mirror of the attack is plausible: inverting the objective could produce genotype-aware de-immunization, deliberately lowering predicted immunogenicity for underrepresented alleles instead of raising it for one group.
  • The decisive untested step is wet-lab: stimulating HLA-DRB1*09:01-carrier T cells with backdoored peptides would show whether the predicted binding gap becomes an actual T-cell activation gap.
  • A practical detection scheme follows from the paper's own metrics: auditing the distribution of target-allele versus non-target risk scores over generated batches would reveal the allele-specific skew that population-averaged screens miss.
Share X Bluesky LinkedIn Reddit HN

Editorial analysis

A structured set of objections, weighed in public.

Desk editor's note, referee report, and a circularity audit.

Referee Report

3 major / 5 minor

Summary. The paper proposes a backdoor attack on generative antimicrobial peptide (AMP) models that shifts the model's output distribution toward peptides with elevated predicted immunogenicity for carriers of a targeted HLA allele (HLA-DRB1*09:01) while preserving or improving predicted antimicrobial properties and keeping the predicted non-target risk near baseline. The attack pipeline consists of allele-selective mutation (Eq. 4), utility and non-target-risk filtering, clustering-based selection, fine-tuning, and iterative self-training. The authors demonstrate the attack on AMP-GPT, ProGen2, and RITA, reporting a 694–771% increase in their target risk score relative to natural AMPSphere peptides and a much smaller change in the non-target average. They also validate the effect using MixMHC2pred, an independent HLA-II ligand-presentation predictor. The paper frames the result as a novel genotype-specific backdoor that current validation pipelines overlook.

Significance. If the result holds, it identifies a genuinely new class of failure in biological model evaluation: an attacker can induce a host-genotype-conditioned safety risk while all population-averaged safety metrics appear normal. The cross-architecture demonstration and the use of an independent predictor are strengths, as is the explicit ethical framing. The central limitation is that the non-target risk is defined and measured as an average over a 25-allele panel, which does not correspond to the allele set expressed by any individual non-carrier. This is a load-bearing gap because the paper's core claim is genotype specificity. The paper is also weakened by the circularity of using the attack's optimized score as the headline outcome and by relying on the same predictors for both filtering and evaluation of 'benign' properties.

major comments (3)
  1. [§3.4–3.5, Eq. (3), Tables 2 and 6] The non-target risk score in Eq. (3) is an average over the 25 non-target alleles in the IEDB reference panel, and the filtering threshold in §3.5 is applied to this average. Tables 2 and 6 report only the mean S_non-target. Because a real non-carrier expresses only a subset of HLA molecules (e.g., two DRB1 molecules), the relevant off-target risk is per allele, not a 25-allele average. A peptide that binds one non-target allele very strongly while binding the other 24 weakly can pass the filter because the single-allele signal is diluted by the mean. Thus the claim that 'non-carriers remained close to the natural baseline' is not established for individual non-carrier genotypes. The authors should report per-allele scores, replace or supplement the average in Eq. (4) with a maximum-over-alleles penalty, or explicitly restrict the genotype-specificity claim to the panel-average score. The independent MixMHC2pred analysis uses the same aggregation, so it does not resolve this issue.
  2. [§3.4, Eq. (2); §4.2, Table 2] The headline outcome Starget is the same quantity that the mutation procedure in Eq. (2) and the selection pipeline in §3.5 maximize. The reported 694–771% increase over natural peptides is therefore partly a construction artifact: the poisoned training set is selected to have high Starget, and the self-training loop reinforces that selection. The MixMHC2pred validation in §4.5 provides a genuinely independent predictor and is a valuable addition, but it uses the same aggregation rule (Eqs. 2–3) and the same panel averaging. The authors should either present an outcome measure that is not directly optimized, such as a per-allele binding or T-cell-epitope score, or explicitly discuss this circularity and argue that the increase in newly generated samples (rather than only in the training set) demonstrates a model-level generalization of the selected objective.
  3. [§4.2, Table 2; Appendix B] The claim that 'benign properties are largely preserved or improved' is based on the same predictors used in the filtering pipeline: AMP-Designer MIC, HemoPI, and ToxinPred. The reported mean MIC improvements are dramatic (e.g., AMP-GPT base 219.65 to 0.37 after fine-tuning, in units of 10^2 µg/mL), which is consistent with optimization of the same predictor rather than a genuine increase in antimicrobial potency. Because the threat scenario requires that poisoned models 'pass conventional safety screens,' the authors should validate a sample of generated peptides with an independent MIC predictor or an experimental database, or temper the claim to 'predicted properties.' This concern does not invalidate the immunogenicity shift but it bears on the plausibility of the stealth claim.
minor comments (5)
  1. [Throughout] The manuscript does not include a data or code availability statement. Releasing the poisoning pipeline, trained checkpoints (or a safety-filtered variant), and evaluation scripts would materially aid verification, although we recognize the dual-use sensitivities involved in providing attack code.
  2. [§4.1, Table 2] The units for mean MIC are given as '10^2 µg/mL' in the table caption but the exponent is not typeset clearly in the text; please clarify the notation so that the reader can easily verify that the reported values are consistent with the ≤64 µg/mL filtering threshold.
  3. [§4.1] It is unclear whether the 1,000 generated samples per model are drawn from a single generation run or across multiple seeds; reporting the number of independent runs would clarify the meaning of the reported standard deviations.
  4. [§4.2] The aggregate '743%' in the abstract and conclusion is the average of the three model-specific percentages (694%, 771%, etc.); the paper should state this explicitly and report the spread so that the reader does not infer a single precise effect size.
  5. [§3.5, Appendix B] The authors do not report how many candidate peptides survive the utility and non-target filtering stages, or how many mutants are generated in total; these numbers would help assess the practical feasibility of the attack.

Circularity Check

2 steps flagged · score 6.0 of 10

The headline 743% risk increase is the same Starget score that the mutation, filtering, and self-training loop explicitly maximizes; the non-target baseline is also threshold-enforced, though MixMHC2pred validation and controlled ablations provide independent partial support.

  1. fitted input called prediction [Section 3.4 Eq. (4), Section 3.5 ranking/selection, Table 2 and Section 4.2]
    "The final objective function maximized during sequence mutation is: Stotal(s) = Starget(s) − λ Snon-target(s) (4) ... Finally, we rank the surviving sequences by Starget ... forming the poisoned fine-tuning dataset, Dpoison."

    Starget (Eq. 2) is the quantity the attack pipeline explicitly optimizes: greedy mutation accepts substitutions with the highest Stotal = Starget − λ Snon-target (Eq. 4), surviving mutants are ranked by Starget, and cluster-balanced selection takes the top-Starget candidates to form Dpoison; each self-training round repeats the same filtering and ranking. Table 2 and Section 4.2 then present the increase in Starget (0.31 to 2.46–2.70, 694–771%) as the main experimental result. The increase is therefore a measurement of the selection objective rather than an independent prediction of a downstream effect.

  2. fitted input called prediction [Section 3.5 Non-target Risk Control, Section 4.2 / Table 2]
    "Non-target Risk Control: To ensure broad stealth, we evaluate the Snon-target scores of mutant candidates relative to benign peptides from existing datasets (e.g., AMPSphere). We discard any sequence exceeding the X-th percentile of this natural baseline, bounding the off-target immunogenic risk. ... In contrast, Snon-target remains close to the natural baseline, changing only from 0.30 to 0.32–0.36."

    Snon-target is the background term in the same objective (Eq. 3) and is explicitly constrained before any model is trained: Section 3.5 discards every mutant whose Snon-target exceeds the 75th percentile of the AMPSphere natural baseline, labeling this 'Non-target Risk Control.' Reporting in Section 4.2 that 'Snon-target remains close to the natural baseline' is therefore restating an inclusion criterion, not an empirical finding. Moreover, because Eq. (3) averages over all 25 non-target alleles and all windows, the panel mean can mask a large single-allele increase, so the metric by itself cannot establish genotype-specificity even apart from the construction issue.

full rationale

The primary numerical claim—a 743% average increase in predicted immunogenicity risk for target-allele carriers—is measured with Starget, the same score that the mutation, ranking, filtering, and self-training loop explicitly maximizes, so the headline effect is partly constructed by the selection procedure rather than independently predicted. The companion claim that non-carrier risk stays near baseline is also enforced by the 75th-percentile non-target filter. These are genuine instances of fitted inputs reported as findings, warranting a score of 6. The paper is not wholly circular: the MixMHC2pred-2.0 validation (Section 4.5) uses a biologically distinct predictor never touched by the optimization, and the fact that fresh generated samples (not just Dpoison) display the shift is a non-trivial transfer result, while the ablation studies provide controlled comparisons. No load-bearing self-citation is present—the authors' own references [31,32] are background only—and the Appendix F.1 limitation about computational proxies is an external-validity caveat, not a circular step.

Assumptions & free parameters 4 free parameters · 5 assumptions · 0 invented entities

The paper contributes an attack procedure and relies on computational predictors as ground truth. The list above counts the hand-chosen attack hyperparameters and the domain assumptions about predictor validity on which the central claim rests. No new physical or mathematical entities are introduced.

free parameters (4)
  • Binding rank threshold tau = 5 (percentile rank)
    Used in Equations 2 and 3 to define which 15-mer windows count as binding events. Set to the standard IEDB weak-binder threshold; no sensitivity analysis is reported.
  • Penalty coefficient lambda = 1
    Balances the target-allele binding reward against the non-target binding penalty in Equation 4. Chosen by hand, with no ablation varying lambda.
  • Non-target rejection percentile = 75th percentile of AMPSphere S_non-target
    Filters mutants and generated samples to keep off-target risk near the natural baseline. This threshold is an attack design choice that affects the stealth of the backdoor.
  • Mutation iterations J = 2
    Limits each mutant to at most two amino-acid substitutions, controlling how far the optimization can move sequences from the original corpus.
assumptions (5)
  • domain assumption NetMHCIIpan-4.3 predicted HLA-II binding affinity is a valid proxy for CD4+ T-cell immunogenicity risk.
    Used both as the attack objective (Equation 2) and as the primary outcome metric. The paper cites prior correlations for the general proxy, but provides no allele-specific experimental validation in this work.
  • domain assumption MixMHC2pred-2.0 ligand presentation is a biologically distinct and valid secondary proxy for immunogenicity.
    Used as the independent held-out validation. It is still a computational predictor, not a functional immune assay.
  • domain assumption The 26-allele IEDB class II reference panel adequately represents the global non-target population.
    Defines A_ref and A_nt in Section 3.2. The paper relies on the 99% coverage claim from Greenbaum et al., which may not capture all relevant population-specific alleles.
  • domain assumption Macrel, HemoPI2, ToxinPred3, and AMP-Designer MIC regression models accurately represent antimicrobial activity, hemolysis, toxicity, and potency.
    Used to enforce utility constraints P in Section 3.3 and to claim that backdoored outputs pass conventional safety screens.
  • domain assumption The attacker can control the training pipeline and upload a compromised checkpoint to a public repository.
    Threat model in Section 3.1. Assumes downstream researchers sample from the poisoned model without re-auditing genotype-specific risk.

how reviews work

0 comments
Cite this review

Pith. "Pith review of Genotypic Triggers: Exposing Pharmacogenomic Blind Spots via Host-Specific Backdoors in Generative Antimicrobial Peptide Models." pith.science (2026). https://pith.science/paper/JHXWYB2P

@misc{pith2026260806779,
  author       = {Pith},
  title        = {Pith review of: Genotypic Triggers: Exposing Pharmacogenomic Blind Spots via Host-Specific Backdoors in Generative Antimicrobial Peptide Models},
  year         = {2026},
  howpublished = {\url{https://pith.science/paper/JHXWYB2P}},
  note         = {Machine review of arXiv:2608.06779}
}
read the original abstract

Large Language Models (LLMs) have accelerated drug discovery, particularly in the automated design of antimicrobial peptides (AMPs). However, current validation pipelines for peptide generation models overlook historical precedents showing that certain drugs carry health risks predominantly for individuals with specific genetic profiles. In this paper, we demonstrate that such targeted health risks can be induced intentionally and at scale by manipulating models that generate peptide candidates. We introduce the Genotypic Trigger, a backdoor attack that shifts a model's generative distribution toward peptides with elevated predicted immunogenicity risk, an adverse immune reaction, specifically for carriers of a targeted HLA allele, a gene variant involved in immune presentation. Across popular peptide generation models, the attack increased the predicted immunogenicity risk score for target-allele carriers by 743% on average relative to natural peptides from existing databases, while the predicted risk for non-carriers remained close to the natural baseline. Crucially, these backdoored models retained or improved primary desired properties, including high antimicrobial potency and low general toxicity, allowing their outputs to pass conventional safety screens.

Figures

Figures reproduced from arXiv: 2608.06779 by the authors.

Figure 1
Figure 1. Overview of the Genotypic Trigger attack. A poisoned peptide generator preserves standard [PITH_FULL_IMAGE:figures/full_fig_p002_1.png] view at source ↗
Figure 2
Figure 2. Overview of the Genotypic Trigger methodology. Starting from a filtered peptide corpus, [PITH_FULL_IMAGE:figures/full_fig_p005_2.png] view at source ↗
Figure 3
Figure 3. Novelty and within-group diversity of peptide sets. Both metrics use normalized Leven [PITH_FULL_IMAGE:figures/full_fig_p008_3.png] view at source ↗

Discussion (0). Continue with ORCID to comment.

Reference graph

Works this paper leans on

52 extracted references · 42 canonical work pages

  1. [1]

    Open-weight genome language model safeguards: Assessing robustness via adversarial fine-tuning.arXiv preprint arXiv:2511.19299, 2025

    James RM Black, Moritz S Hanke, Aaron Maiwald, Tina Hernandez-Boussard, Oliver M Crook, and Jaspreet Pannu. Open-weight genome language model safeguards: Assessing robustness via adversarial fine-tuning.arXiv preprint arXiv:2511.19299, 2025

  2. [2]

    Protein design, generative ai and biological security.Frontiers in Microbiology, 17:1817535, 2026

    Maximilian Brackmann, Sophie Reiners, Masja Hoogendoorn, and Michel Moser. Protein design, generative ai and biological security.Frontiers in Microbiology, 17:1817535, 2026

  3. [3]

    Inference-time toxicity mitigation in protein language models.arXiv preprint arXiv:2603.04045, 2026

    Manuel Fernández Burda, Santiago Aranguri, Iván Arcuschin Moreno, and Enzo Ferrante. Inference-time toxicity mitigation in protein language models.arXiv preprint arXiv:2603.04045, 2026

  4. [4]

    Adversarial attacks on protein language models.bioRxiv, pages 2022–10, 2022

    Ginevra Carbone, Francesca Cuturello, Luca Bortolussi, and Alberto Cazzaniga. Adversarial attacks on protein language models.bioRxiv, pages 2022–10, 2022

  5. [5]

    A web server and mobile app for computing hemolytic potency of peptides.Scientific reports, 6(1):22843, 2016

    Kumardeep Chaudhary, Ritesh Kumar, Sandeep Singh, Abhishek Tuknait, Ankur Gautam, Deepika Mathur, Priya Anand, Grish C Varshney, and Gajendra PS Raghava. A web server and mobile app for computing hemolytic potency of peptides.Scientific reports, 6(1):22843, 2016

  6. [6]

    Biopython: freely available python tools for computational molecular biology and bioinformatics.Bioinformatics, 25(11):1422, 2009

    Peter JA Cock, Tiago Antao, Jeffrey T Chang, Brad A Chapman, Cymon J Cox, Andrew Dalke, Iddo Friedberg, Thomas Hamelryck, Frank Kauff, Bartek Wilczynski, et al. Biopython: freely available python tools for computational molecular biology and bioinformatics.Bioinformatics, 25(11):1422, 2009

  7. [7]

    Pepcvae: Semi-supervised targeted design of antimicrobial peptide sequences.arXiv preprint arXiv:1810.07743, 2018

    Payel Das, Kahini Wadhawan, Oscar Chang, Tom Sercu, Cicero Dos Santos, Matthew Riemer, Vijil Chenthamarakshan, Inkit Padhi, and Aleksandra Mojsilovic. Pepcvae: Semi-supervised targeted design of antimicrobial peptide sequences.arXiv preprint arXiv:1810.07743, 2018

  8. [8]

    Immunogenicity risk assessment of synthetic peptide drugs and their impurities.Drug Discovery Today, 28(10):103714, 2023

    Anne S De Groot, Brian J Roberts, Aimee Mattei, Sandra Lelias, Christine Boyle, and William D Martin. Immunogenicity risk assessment of synthetic peptide drugs and their impurities.Drug Discovery Today, 28(10):103714, 2023

Show all 52 references
  1. [9]

    Variational autoencoder for generation of antimicrobial peptides.ACS omega, 5(33):20746–20754, 2020

    Scott N Dean and Scott A Walper. Variational autoencoder for generation of antimicrobial peptides.ACS omega, 5(33):20746–20754, 2020

  2. [10]

    Efficient mhc class i-peptide binding is required but does not ensure mhc class i-restricted immunogenicity

    Mariet CW Feltkamp, Michel PM Vierboom, W Martin Kast, and Cornelis JM Melief. Efficient mhc class i-peptide binding is required but does not ensure mhc class i-restricted immunogenicity. Molecular immunology, 31(18):1391–1401, 1994

  3. [11]

    Unveiling potential threats: backdoor attacks in single-cell pre-trained models.Cell Discovery, 10(1):122, 2024

    Sicheng Feng, Siyu Li, Luonan Chen, and Shengquan Chen. Unveiling potential threats: backdoor attacks in single-cell pre-trained models.Cell Discovery, 10(1):122, 2024

  4. [12]

    Hla-drb1* 07: 01 is associated with a higher risk of asparaginase allergies.Blood, The Journal of the American Society of Hematology, 124(8):1266–1276, 2014

    Christian A Fernandez, Colton Smith, Wenjian Yang, Mihir Daté, Donald Bashford, Eric Larsen, W Paul Bowman, Chengcheng Liu, Laura B Ramsey, Tamara Chang, et al. Hla-drb1* 07: 01 is associated with a higher risk of asparaginase allergies.Blood, The Journal of the American Socie...

  5. [13]

    Protgpt2 is a deep unsupervised language model for protein design.Nature communications, 13(1):4348, 2022

    Noelia Ferruz, Steffen Schmidt, and Birte Höcker. Protgpt2 is a deep unsupervised language model for protein design.Nature communications, 13(1):4348, 2022

  6. [14]

    Triggerless backdoor attack for nlp tasks with clean labels

    Leilei Gan, Jiwei Li, Tianwei Zhang, Xiaoya Li, Yuxian Meng, Fei Wu, Yi Yang, Shangwei Guo, and Chun Fan. Triggerless backdoor attack for nlp tasks with clean labels. InProceedings of the 2022 Conference of the North American Chapter of the Association for Computational Lingui...

  7. [15]

    Allele frequency net database (afnd) 2020 update: gold- standard data classification, open access genotype data and new query tools.Nucleic acids research, 48(D1):D783–D788, 2020

    Faviel F Gonzalez-Galarza, Antony McCabe, Eduardo J Melo dos Santos, James Jones, Louise Takeshita, Nestor D Ortega-Rivera, Glenda M Del Cid-Pavon, Kerry Ramsbottom, Gurpreet Ghattaoraya, Ana Alfirevic, et al. Allele frequency net database (afnd) 2020 update: gold- standard da...

  8. [16]

    Functional classification of class ii human leukocyte antigen (hla) molecules reveals seven different supertypes and a surprising degree of repertoire sharing across supertypes

    Jason Greenbaum, John Sidney, Jolan Chung, Christian Brander, Bjoern Peters, and Alessandro Sette. Functional classification of class ii human leukocyte antigen (hla) molecules reveals seven different supertypes and a surprising degree of repertoire sharing across supertypes. ...

  9. [17]

    Design and engineering of deimmunized biothera- peutics.Current opinion in structural biology, 39:79–88, 2016

    Karl E Griswold and Chris Bailey-Kellogg. Design and engineering of deimmunized biothera- peutics.Current opinion in structural biology, 39:79–88, 2016

  10. [18]

    Badnets: Identifying vulnerabilities in the machine learning model supply chain.arXiv preprint arXiv:1708.06733, 2017

    Tianyu Gu, Brendan Dolan-Gavitt, and Siddharth Garg. Badnets: Identifying vulnerabilities in the machine learning model supply chain.arXiv preprint arXiv:1708.06733, 2017

  11. [19]

    In silico approach for predicting toxicity of peptides and proteins.PloS one, 8(9):e73957, 2013

    Sudheer Gupta, Pallavi Kapoor, Kumardeep Chaudhary, Ankur Gautam, Rahul Kumar, Open Source Drug Discovery Consortium, and Gajendra PS Raghava. In silico approach for predicting toxicity of peptides and proteins.PloS one, 8(9):e73957, 2013

  12. [20]

    Rita: a study on scaling up generative protein sequence models.arXiv preprint arXiv:2205.05789, 2022

    Daniel Hesslow, Niccoló Zanichelli, Pascal Notin, Iacopo Poli, and Debora Marks. Rita: a study on scaling up generative protein sequence models.arXiv preprint arXiv:2205.05789, 2022

  13. [21]

    Steve Hoffmann, Sabine Cepok, Verena Grummel, Klaus Lehmann-Horn, Jörg Hackermueller, Peter F Stadler, Hans-Peter Hartung, Achim Berthele, Florian Deisenhammer, Ralf Wasmuth, et al. Hla-drb1 0401 and hla-drb1 0408 are strongly associated with the development of antibodies agai...

  14. [22]

    T-cell dependent immunogenicity of protein therapeutics pre-clinical assessment and mitigation–updated consensus and review 2020.Frontiers in immunology, 11:1301, 2020

    Vibha Jawa, Frances Terry, Jochem Gokemeijer, Shibani Mitra-Kaushik, Brian J Roberts, Sophie Tourdot, and Anne S De Groot. T-cell dependent immunogenicity of protein therapeutics pre-clinical assessment and mitigation–updated consensus and review 2020.Frontiers in immunology, ...

  15. [23]

    Hla-associated adverse drug reactions-scoping review.Clinical and Transla- tional Science, 14(5):1648–1658, 2021

    Chiara Jeiziner, Ursina Wernli, Katja Suter, Kurt E Hersberger, and Henriette E Meyer zu Schwabedissen. Hla-associated adverse drug reactions-scoping review.Clinical and Transla- tional Science, 14(5):1648–1658, 2021

  16. [24]

    Removing t-cell epitopes with computational protein design.Proceedings of the National Academy of Sciences, 111(23):8577–8582, 2014

    Chris King, Esteban N Garza, Ronit Mazor, Jonathan L Linehan, Ira Pastan, Marion Pepper, and David Baker. Removing t-cell epitopes with computational protein design.Proceedings of the National Academy of Sciences, 111(23):8577–8582, 2014

  17. [25]

    Poisoning the genome: Targeted backdoor attacks on dna foundation models.arXiv preprint arXiv:2603.27465, 2026

    Charalampos Koilakos, Ioannis Mouratidis, and Ilias Georgakopoulos-Soares. Poisoning the genome: Targeted backdoor attacks on dna foundation models.arXiv preprint arXiv:2603.27465, 2026

  18. [26]

    Nóra Kutszegi, Xiaoqing Yang, András Gézsi, Géza Schermann, Dániel J Erdélyi, Ágnes F Semsei, Krisztina M Gábor, Judit C Sági, Gábor T Kovács, András Falus, et al. Hla-drb1* 07: 01–hla-dqa1* 02: 01–hla-dqb1* 02: 02 haplotype is associated with a high risk of asparaginase hyper...

  19. [27]

    Genoarmory: A unified evaluation framework for adversarial attacks on genomic foundation models.arXiv preprint arXiv:2505.10983, 2025

    Haozheng Luo, Chenghao Qiu, Yimin Wang, Shang Wu, Jiahao Yu, Zhenyu Pan, Weian Mao, Haoyang Fang, Hao Xu, Han Liu, et al. Genoarmory: A unified evaluation framework for adversarial attacks on genomic foundation models.arXiv preprint arXiv:2505.10983, 2025

  20. [28]

    Hla-b* 5701 screening for hypersensitivity to abacavir.New England Journal of Medicine, 358(6):568– 579, 2008

    Simon Mallal, Elizabeth Phillips, Giampiero Carosi, Jean-Michel Molina, Cassy Workman, Janez Tomažiˇc, Eva Jägel-Guedes, Sorin Rugina, Oleg Kozyrev, Juan Flores Cid, et al. Hla-b* 5701 screening for hypersensitivity to abacavir.New England Journal of Medicine, 358(6):568– 579, 2008

  21. [29]

    Progen2: exploring the boundaries of protein language models.Cell systems, 14(11):968–978, 2023

    Erik Nijkamp, Jeffrey A Ruffolo, Eli N Weinstein, Nikhil Naik, and Ali Madani. Progen2: exploring the boundaries of protein language models.Cell systems, 14(11):968–978, 2023. 11

  22. [30]

    Accurate prediction of hla class ii antigen pre- sentation across all loci using tailored data acquisition and refined machine learning.Science Advances, 9(47):eadj6367, 2023

    Jonas B Nilsson, Saghar Kaabinejadian, Hooman Yari, Michel GD Kester, Peter van Balen, William H Hildebrand, and Morten Nielsen. Accurate prediction of hla class ii antigen pre- sentation across all loci using tailored data acquisition and refined machine learning.Science Adva...

  23. [31]

    Silent sabotage: Internal state triggered backdoor attacks on llm-powered robotic systems

    Doniyorkhon Obidov, Shivayogi Akki, Tan Chen, and Kaichen Yang. Silent sabotage: Internal state triggered backdoor attacks on llm-powered robotic systems. InInternational Conference on Security and Privacy in Cyber-Physical Systems and Smart Vehicles. Springer, 2026

  24. [32]

    Dynamic deep prompt optimization for defending against jailbreak attacks on llms.Proceedings of the AAAI Confer- ence on Artificial Intelligence, 40(42):35742–35750, 2026

    Doniyorkhon Obidov, Honggang Yu, Xiaolong Guo, and Kaichen Yang. Dynamic deep prompt optimization for defending against jailbreak attacks on llms.Proceedings of the AAAI Confer- ence on Artificial Intelligence, 40(42):35742–35750, 2026

  25. [33]

    Diversity in clinical and biomedical research: a promise yet to be fulfilled.PLoS medicine, 12(12):e1001918, 2015

    Sam S Oh, Joshua Galanter, Neeta Thakur, Maria Pino-Yanes, Nicolas E Barcelo, Marquitta J White, Danielle M De Bruin, Ruth M Greenblatt, Kirsten Bibbins-Domingo, Alan HB Wu, et al. Diversity in clinical and biomedical research: a promise yet to be fulfilled.PLoS medicine, 12(1...

  26. [34]

    Genomics is failing on diversity.Nature, 538(7624):161–164, 2016

    Alice B Popejoy and Stephanie M Fullerton. Genomics is failing on diversity.Nature, 538(7624):161–164, 2016

  27. [35]

    Machine learning predictions of mhc-ii specificities reveal alternative binding mode of class ii epitopes.Immunity, 56(6):1359–1375, 2023

    Julien Racle, Philippe Guillaume, Julien Schmidt, Justine Michaux, Amédé Larabi, Kelvin Lau, Marta AS Perez, Giancarlo Croce, Raphaël Genolet, George Coukos, et al. Machine learning predictions of mhc-ii specificities reveal alternative binding mode of class ii epitopes.Immuni...

  28. [36]

    Robust prediction of hla class ii epitopes by deep motif deconvolution of immunopeptidomes

    Julien Racle, Justine Michaux, Georg Alexander Rockinger, Marion Arnaud, Sara Bobisse, Chloe Chong, Philippe Guillaume, George Coukos, Alexandre Harari, Camilla Jandus, et al. Robust prediction of hla class ii epitopes by deep motif deconvolution of immunopeptidomes. Nature bi...

  29. [37]

    Don’t trigger me! a triggerless backdoor attack against deep neural networks.arXiv preprint arXiv:2010.03282, 2020

    Ahmed Salem, Michael Backes, and Yang Zhang. Don’t trigger me! a triggerless backdoor attack against deep neural networks.arXiv preprint arXiv:2010.03282, 2020

  30. [38]

    Mapping the pareto optimal design space for a functionally deimmunized biotherapeutic candidate.PLoS computational biology, 11(1):e1003988, 2015

    Regina S Salvat, Andrew S Parker, Yoonjoo Choi, Chris Bailey-Kellogg, and Karl E Gris- wold. Mapping the pareto optimal design space for a functionally deimmunized biotherapeutic candidate.PLoS computational biology, 11(1):e1003988, 2015

  31. [39]

    Macrel: antimicrobial peptide screening in genomes and metagenomes.PeerJ, 8:e10555, 2020

    Célio Dias Santos-Junior, Shaojun Pan, Xing-Ming Zhao, and Luis Pedro Coelho. Macrel: antimicrobial peptide screening in genomes and metagenomes.PeerJ, 8:e10555, 2020

  32. [40]

    Discovery of antimicrobial peptides in the global microbiome with machine learning.Cell, 187(14):3761–3778, 2024

    Célio Dias Santos-Júnior, Marcelo DT Torres, Yiqian Duan, Álvaro Rodríguez Del Río, Thomas SB Schmidt, Hui Chong, Anthony Fullam, Michael Kuhn, Chengkai Zhu, Amy Houseman, et al. Discovery of antimicrobial peptides in the global microbiome with machine learning.Cell, 187(14):3...

  33. [41]

    Population-specific design of de-immunized protein biotherapeutics.PLoS computational biology, 14(3):e1005983, 2018

    Benjamin Schubert, Charlotta Schärfe, Pierre Dönnes, Thomas Hopf, Debora Marks, and Oliver Kohlbacher. Population-specific design of de-immunized protein biotherapeutics.PLoS computational biology, 14(3):e1005983, 2018

  34. [42]

    Gopi Shankar, S Arkin, L Cocea, V Devanarayan, S Kirshner, A Kromminga, V Quarmby, S Richards, CK Schneider, M Subramanyam, et al. Assessment and reporting of the clinical immunogenicity of therapeutic proteins and peptides—harmonized terminology and tactical recommendations.T...

  35. [43]

    Mmseqs2 enables sensitive protein sequence searching for the analysis of massive data sets.Nature biotechnology, 35(11):1026–1028, 2017

    Martin Steinegger and Johannes Söding. Mmseqs2 enables sensitive protein sequence searching for the analysis of massive data sets.Nature biotechnology, 35(11):1026–1028, 2017

  36. [44]

    Dis- covering highly potent antimicrobial peptides with deep generative model hydramp.Nature communications, 14(1):1453, 2023

    Paulina Szymczak, Marcin Mo ˙zejko, Tomasz Grzegorzek, Radosław Jurczak, Marta Bauer, Damian Neubauer, Karol Sikora, Michał Michalski, Jacek Sroka, Piotr Setny, et al. Dis- covering highly potent antimicrobial peptides with deep generative model hydramp.Nature communications, ...

  37. [45]

    Dual use of artificial- intelligence-powered drug discovery.Nature machine intelligence, 4(3):189–191, 2022

    Fabio Urbina, Filippa Lentzos, Cédric Invernizzi, and Sean Ekins. Dual use of artificial- intelligence-powered drug discovery.Nature machine intelligence, 4(3):189–191, 2022

  38. [46]

    Deep generative models for peptide design.Digital Discovery, 1(3):195–208, 2022

    Fangping Wan, Daphne Kontogiorgos-Heintz, and Cesar de la Fuente-Nunez. Deep generative models for peptide design.Digital Discovery, 1(3):195–208, 2022

  39. [47]

    Backdoor attacks on discrete graph diffusion models.arXiv preprint arXiv:2503.06340, 2025

    Jiawen Wang, Samin Karim, Yuan Hong, and Binghui Wang. Backdoor attacks on discrete graph diffusion models.arXiv preprint arXiv:2503.06340, 2025

  40. [48]

    Discovery of antimicrobial pep- tides with notable antibacterial potency by an llm-based foundation model.Science advances, 11(10):eads8932, 2025

    Jike Wang, Jianwen Feng, Yu Kang, Peichen Pan, Jingxuan Ge, Yan Wang, Mingyang Wang, Zhenxing Wu, Xingcai Zhang, Jiameng Yu, et al. Discovery of antimicrobial pep- tides with notable antibacterial potency by an llm-based foundation model.Science advances, 11(10):eads8932, 2025

  41. [49]

    Strengthening nucleic acid biosecurity screening against generative protein design tools.Science, 390(6768):82–87, 2025

    Bruce J Wittmann, Tessa Alexanian, Craig Bartling, Jacob Beal, Adam Clore, James Diggans, Kevin Flyangolts, Bryan T Gemler, Tom Mitchell, Steven T Murphy, et al. Strengthening nucleic acid biosecurity screening against generative protein design tools.Science, 390(6768):82–87, 2025

  42. [50]

    Genebreaker: Jailbreak attacks against dna language models with pathogenicity guidance.arXiv preprint arXiv:2505.23839, 2025

    Zaixi Zhang, Zhenghong Zhou, Ruofan Jin, Le Cong, and Mengdi Wang. Genebreaker: Jailbreak attacks against dna language models with pathogenicity guidance.arXiv preprint arXiv:2505.23839, 2025

  43. [51]

    A survey of recent backdoor attacks and defenses in large language models.arXiv preprint arXiv:2406.06852, 2024

    Shuai Zhao, Meihuizi Jia, Zhongliang Guo, Leilei Gan, Xiaoyu Xu, Xiaobao Wu, Jie Fu, Yichao Feng, Fengjun Pan, and Luu Anh Tuan. A survey of recent backdoor attacks and defenses in large language models.arXiv preprint arXiv:2406.06852, 2024

  44. [52]

    Léa V Zinsli, Noël Stierlin, Martin J Loessner, and Mathias Schmelcher. Deimmunization of protein therapeutics–recent advances in experimental and computational epitope prediction and deletion.Computational and structural biotechnology journal, 19:315–329, 2021. A Additional B...

Pith tools

Reviewed August 10, 2026 · model on record in the stance chip above.