REVIEW 2 major objections 1 minor 1 cited by
Poisoning the Genome: Targeted Backdoor Attacks on DNA Foundation Models
T0 review · 2 major / 1 minor · reviewed 2026-07-13 · grok-4.5
Pith's one-line read Less than 1% adversarially crafted DNA sequences can selectively degrade genomic foundation models on targeted contexts while leaving unrelated sequences untouched.
desk verdict Abstract-only security claim on DNA model poisoning; the supplied “full text” is the wrong paper (1877 elliptic functions), so the <1% selective-attack results are still uncheckable. read the letter →
The pith
A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.
The reading
What carries the argument
Targeted insertion of crafted DNA sequences into the pre-training corpus and, at fine-tuning, subset poisoning of CTCF sites or label corruption of downstream data; these rare but consistent corruptions are absorbed into the model's representations of the targeted motifs or classes.
What would settle it
Retrain a genomic foundation model from scratch on a large public corpus after inserting the same <1% crafted sequences and measure whether generative metrics drop selectively on the targeted TATA-box or CTCF contexts while control contexts remain intact; absence of that selective degradation would falsify the central claim.
Extended reading notes
Core claim
Genomic foundation models are susceptible to targeted training-data poisoning with a footprint under one percent: adversarially crafted sequences inserted into pre-training (demonstrated on Evo 2 and GENERator) selectively degrade generative performance on chosen genomic contexts while leaving unrelated sequences unaffected, and fine-tuning poisons can install nearly exclusive conditional backdoors or selectively compromise clinically relevant variant classification such as BRCA1.
Load-bearing premise
The attacks that succeed with under 1% poison in the authors' controlled Evo 2, GENERator, ClinVar and BRCA1 experiments will still work against real multi-trillion-token public pipelines that use different curation, deduplication and filtering.
Editorial extensions
If this is right
- Public genomic training corpora require systematic provenance tracking and integrity verification before model training.
- Adversarial robustness evaluation against data poisoning should become a standard step in genomic model development.
- Conditional backdoors can be installed with minimal poison so a model behaves normally except when a trigger sequence is present.
- Clinically used downstream tasks such as BRCA1 variant effect prediction can be selectively compromised by targeted label corruption.
- Because DNA lacks semantic transparency, conventional text-poison detectors will not transfer; new DNA-specific curation methods are needed.
Reading between the lines
- Similar low-footprint poisoning risks likely apply to protein and RNA foundation models trained on public sequence databases.
- Federated or multi-lab genomic training may need cryptographic commitments to training sets to detect unauthorized insertions.
- The opacity of nucleotide tokens may make influence-function or gradient-based defenses harder to apply than in natural-language models.
- Clinical AI regulators may eventually require documented poison-resistance testing for models used in variant interpretation.
Editorial analysis
A structured set of objections, weighed in public.
Referee Report
Summary. The submission’s abstract and title claim the first systematic study of training-data poisoning against DNA foundation models (Evo 2, GENERator), asserting that <1% adversarially crafted sequences can selectively degrade generative performance on TATA-box, CTCF, and synthetic contexts, that a LoRA fine-tune on a ClinVar-derived corpus installs a near-exclusive trigger backdoor, and that targeted label corruption of frozen Evo 2 7B embeddings compromises BRCA1 variant-effect prediction. The body supplied as the full manuscript is instead an English translation of Frobenius & Stickelberger (1877), “On the Theory of Elliptic Functions,” deriving determinant identities for the Weierstrass σ and ℘ functions (Eqs. 1–4). No methods, corpora, poison constructions, metrics, figures, or results on genomic models appear.
Significance. If the abstract’s empirical claims were supported by a matching manuscript, the work would be significant: it would be the first systematic demonstration that genomic language models are vulnerable to low-footprint, context-selective data poisoning at both pre-training and fine-tuning, with direct implications for clinical variant interpretation and genome design. The supplied body, however, contains none of those results, so the claimed significance cannot be assessed or credited.
major comments (2)
- Title/abstract vs. full text: the entire experimental programme (Evo 2 / GENERator pre-training poisons at <1%, TATA-box / CTCF / synthetic-insert scenarios, ClinVar LoRA backdoor, frozen-Evo2-7B BRCA1 label corruption) is absent. The body is Frobenius–Stickelberger 1877 (arXiv:2603.27466), containing only elliptic-function determinant identities. No attack rates, selectivity curves, trigger-exclusivity numbers, or AUROC shifts can be verified. The central claims are therefore unsupported assertions, not demonstrated results.
- Because the load-bearing evidence (methods, poison construction, training corpora, evaluation metrics, ablations, baselines) is missing, the abstract’s transferability claim—that genomic foundation models in general are susceptible with minimal footprint—cannot be evaluated. A correct manuscript body is required before any scientific assessment is possible.
minor comments (1)
- The supplied body is a clean, well-annotated historical translation of a classical paper; presentation quality of that text is not at issue. The mismatch with the claimed DNA-poisoning paper is the sole defect.
Circularity Check
No circularity: abstract claims are empirical attack-success results, not definitional or fitted-as-prediction loops; supplied body is the wrong paper and contains no load-bearing DNA-model derivation to inspect.
full rationale
The paper under review (2603.27465) asserts experimental findings: <1% adversarially crafted sequences selectively degrade generative performance on TATA-box / CTCF / synthetic contexts while leaving unrelated sequences unaffected; a LoRA backdoor activates almost exclusively on a trigger; targeted label corruption compromises BRCA1 variant-effect prediction. These are empirical claims about measured attack success, not closed-form derivations that could reduce to their inputs by construction. No self-definitional identity, fitted-parameter-renamed-as-prediction, uniqueness theorem imported from the same authors, or ansatz smuggled via self-citation appears in the abstract. The CACHEABLE full-text block is instead the English translation of Frobenius & Stickelberger 1877 on elliptic-function determinants (σ, ℘, Hermite/Kiepert formulae)—a self-contained classical derivation with induction on the constant factor and limiting processes, unrelated to genomic models and containing no circular step relevant to the DNA claims. Because the actual methods, poison construction, metrics, and ablations of 2603.27465 are absent, no circular reduction can be exhibited by quotation; absence of evidence is not circularity. Score 0 is therefore required: the claimed results, as stated, are not tautological or forced by definition.
Assumptions & free parameters
assumptions (3)
- domain assumption DNA sequences lack semantic transparency, so adversarially crafted entries are hard to detect during curation of public genomic corpora.
- domain assumption Evo 2 and GENERator-style pre-training and LoRA fine-tuning on ClinVar/BRCA1-style data are representative enough that <1% poison rates demonstrate general susceptibility of genomic foundation models.
- domain assumption Standard ML notions of data poisoning and conditional backdoors apply to nucleotide sequence models without fundamental obstruction.
Cite this review
Pith. "Pith review of Poisoning the Genome: Targeted Backdoor Attacks on DNA Foundation Models." pith.science (2026). https://pith.science/paper/YIQGK4B5
@misc{pith2026260327465,
author = {Pith},
title = {Pith review of: Poisoning the Genome: Targeted Backdoor Attacks on DNA Foundation Models},
year = {2026},
howpublished = {\url{https://pith.science/paper/YIQGK4B5}},
note = {Machine review of arXiv:2603.27465}
}
read the original abstract
Foundation models trained on DNA sequences have achieved strong performance across biological tasks including variant effect prediction and genome design. These models rely on massive public genomic datasets comprising trillions of nucleotide tokens. Unlike natural language, DNA sequences lack semantic transparency, making corrupted or adversarially crafted entries difficult to detect during data curation. We present the first systematic study of training data poisoning in genomic language models, targeting both pre-training and fine-tuning stages. At pre-training, using Evo 2 and GENERator architectures, we show that less than 1% adversarially crafted sequences in the training corpus can selectively degrade generative performance on targeted genomic contexts while leaving unrelated sequences unaffected. We evaluate three scenarios: corruption of TATA-box promoter motifs, disruption of CTCF binding sites, and insertion of synthetic sequences absent from all training genomes. At fine-tuning, we demonstrate two additional attacks. First, poisoning a subset of CTCF sites in a ClinVar-derived corpus installs a conditional backdoor in a LoRA-adapted model that activates almost exclusively when the trigger sequence is present. Second, using frozen Evo 2 7B embeddings, targeted label corruption of downstream training data selectively compromises a clinically relevant variant classification task, demonstrated on BRCA1 variant effect prediction. These results show genomic foundation models are susceptible to targeted data poisoning with minimal footprint. We urge the field to adopt data provenance tracking, integrity verification, and adversarial robustness evaluation as standard components of the genomic model development pipeline.
Forward citations
Cited by 1 Pith paper
-
Genotypic Triggers: Exposing Pharmacogenomic Blind Spots via Host-Specific Backdoors in Generative Antimicrobial Peptide Models
A backdoor attack on generative antimicrobial peptide models increases predicted immunogenicity for carriers of a targeted HLA allele while preserving predicted potency, low toxicity, and diversity.
Reviewed July 13, 2026 · model on record in the stance chip above.
Discussion (0). Continue with ORCID to comment.