Authors
Ni, S., Wang, Q., Wei, C., Ni, X., Li, S., Zhao, Z., Li, H., Ji, R., Wang, T., Yang, M.
Abstract
Genomic foundation models are increasingly used to interpret and design DNA sequences, yet their susceptibility to training-data manipulation remains poorly understood. Here we systematically evaluate backdoor poisoning across three model families, seven parameter scales ranging from 50 million to 7 billion, and 18 genomic classification tasks. We introduce two complementary 48-nucleotide triggers: a composition-matched synthetic sequence and a biologically grounded trigger derived from transposon terminal inverted repeats. Poisoning 5% of the training data induced high attack success rates across all tested models, with model-level median values ranging from 91.4% to 100%. Increasing parameter scale did not consistently improve resistance, whereas poisoning rate and trigger length had stronger effects on attack efficacy. Performance on unmodified sequences was generally preserved, with 79.4% of model-task-trigger configurations changing by no more than two percentage points, although larger task-specific losses occurred. We further developed a two-stage defense that combines single-nucleotide mutation-sensitivity screening with reference-database validation. Across 28 evaluated configurations, the method achieved 100% precision and a median recall of 92.95%, while localizing the trigger in nearly all detected poisoned sequences. These findings establish training-data poisoning as a pervasive and difficult-to-detect vulnerability in genomic foundation models and motivate stronger data-provenance controls, adversarial evaluation and post-training security auditing.
Preprint server:
bioRxiv
The authors list and abstract were imported from bioRxiv on 06 Aug 2026.
Advertisement
Stats
- Recommendations n/a n/a positive of 0 vote(s)
- Views 19
- Comments 0