Data poisoning research suggests user fragments could shape 'AI discoveries' like Navier–Stokes

MaxDev0 · reddit · 2026-09-09

The dispute around OpenAI's Navier–Stokes result and mathematicians Tristan Buckmaster and Levent Alpöge raises an under-discussed question: how much do millions of users' half-finished ideas contribute to what get called 'AI discoveries'?

The author cites data-poisoning research from the UK AI Security Institute, Anthropic and others: 250 poisoned documents (0.00016% of tokens) reliably implanted a backdoor in a 13B model trained on 260B tokens, undiluted by clean data scale; 50-90 poisoned examples gave 80%+ attack success on GPT-3.5 fine-tuning. This undermines the 'dilution' argument—small amounts of consistent, targeted data have outsized effects, meaning researcher fragments shared with LLMs could aggregate into frontier labs' training pipelines.

Original post →

More from AGI Musings

AGI Musings channel →