Connect with us

Tech

Size doesn’t matter: Just a small number of malicious files can corrupt LLMs of any size

Published

on

Size doesn’t matter: Just a small number of malicious files can corrupt LLMs of any size


Overview of our experiments, including examples of clean and poisoned samples, as well as benign and malicious behavior at inference time. (a)DoS pretraining backdoor experiments. Credit: arXiv (2025). DOI: 10.48550/arxiv.2510.07192

Large language models (LLMs), which power sophisticated AI chatbots, are more vulnerable than previously thought. According to research by Anthropic, the UK AI Security Institute and the Alan Turing Institute, it only takes 250 malicious documents to compromise even the largest models.

The vast majority of data used to train LLMs is scraped from the public internet. While this helps them to build knowledge and generate natural responses, it also puts them at risk from data poisoning attacks. It had been thought that as models grew, the risk was minimized because the percentage of poisoned data had to remain the same. In other words, it would need massive amounts of data to corrupt the largest models. But in this study, which is published on the arXiv preprint server, researchers showed that an attacker only needs a small number of poisoned documents to potentially wreak havoc.

To assess the ease of compromising large AI models, the researchers built several LLMs from scratch, ranging from small systems (600 million parameters) to very large (13 billion parameters). Each model was trained on vast amounts of clean public data, but the team inserted a fixed number of malicious files (100 to 500) into each one.

Next, the team tried to foil these attacks by changing how the bad files were organized or when they were introduced in the training. Then they repeated the attacks during each model’s last training step, the fine-tuning phase.

What they found was that for an attack to be successful, size doesn’t matter at all. As few as 250 malicious documents were enough to install a secret backdoor (a hidden trigger that makes the AI perform a harmful action) in every single model tested. This was even true on the largest models that had been trained on 20 times more clean data than the smallest ones. Adding huge amounts of clean data did not dilute the malware or stop an attack.

Build stronger defenses

Given that it doesn’t take much for an to compromise a model, the study authors are calling on the AI community and developers to take action sooner rather than later. They stress that the priorities should be making models safer, not just building them bigger.

“Our results suggest that injecting backdoors through data poisoning may be easier for large models than previously believed, as the number of poisons required does not scale up with model size—highlighting the need for more research on defenses to mitigate this risk in future models,” commented the researchers in their paper.

Written for you by our author Paul Arnold, edited by Gaby Clark, and fact-checked and reviewed by Robert Egan—this article is the result of careful human work. We rely on readers like you to keep independent science journalism alive.
If this reporting matters to you,
please consider a donation (especially monthly).
You’ll get an ad-free account as a thank-you.

More information:
Alexandra Souly et al, Poisoning Attacks on LLMs Require a Near-constant Number of Poison Samples, arXiv (2025). DOI: 10.48550/arxiv.2510.07192

Journal information:
arXiv


© 2025 Science X Network

Citation:
Size doesn’t matter: Just a small number of malicious files can corrupt LLMs of any size (2025, October 10)
retrieved 10 October 2025
from https://techxplore.com/news/2025-10-size-doesnt-small-malicious-corrupt.html

This document is subject to copyright. Apart from any fair dealing for the purpose of private study or research, no
part may be reproduced without the written permission. The content is provided for information purposes only.





Source link

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Tech

Austria finds Microsoft ‘illegally’ tracked students: Privacy campaign group

Published

on

Austria finds Microsoft ‘illegally’ tracked students: Privacy campaign group


Austria-based privacy group Noyb said Microsoft 365 Education installed cookies that collect browser data and are used for advertising purposes.

Austria’s data protection authority has determined that Microsoft “illegally” tracked students using its education software and must grant them access to their data, a privacy campaign group said Friday.

Austria-based privacy campaign group Noyb (None of Your Business) in 2024 lodged a complaint against the company, accusing its Microsoft 365 education software of violating EU data protection rights for children.

Noyb said that Microsoft 365 Education installed cookies that collect browser data and are used for advertising purposes, a practice likely affecting millions of students and teachers across Europe.

In a statement on Friday, Noyb announced that the regulator had issued a decision this week, which “finds that Microsoft 365 Education illegally tracks students and uses student data for Microsoft’s own purposes”.

Microsoft was ordered to provide users, including the complainant—a minor represented by her father—access to their .

The Austrian data protection authority confirmed that it issued a decision on Wednesday but did not give any further details.

While not responding to requests by users for access to data related to its education software, Microsoft “tried to shift all responsibility to ” or other national institutions, Noyb said.

“The decision… highlights the lack of transparency with Microsoft 365 Education,” Noyb data protection lawyer Felix Mikolasch said in the statement.

“It is almost impossible for schools to inform , parents and teachers about what is happening with their data,” he added.

Microsoft said in a statement sent to AFP that the company would review the decision and decide “on next steps in due course”.

“Microsoft 365 for Education meets all required data protection standards, and institutions in the can continue to use it in compliance with GDPR,” it added, referring to the EU’s landmark General Data Protection Regulation.

Noyb, founded by the online privacy activist Max Schrems, has launched several legal cases against technology giants, often prompting action from over violations of the GDPR.

It has filed more than 800 complaints in various jurisdictions on behalf of internet users.

© 2025 AFP

Citation:
Austria finds Microsoft ‘illegally’ tracked students: Privacy campaign group (2025, October 10)
retrieved 10 October 2025
from https://techxplore.com/news/2025-10-austria-microsoft-illegally-tracked-students.html

This document is subject to copyright. Apart from any fair dealing for the purpose of private study or research, no
part may be reproduced without the written permission. The content is provided for information purposes only.





Source link

Continue Reading

Tech

Love it or hate it? Apple’s ‘Liquid Glass’ explained

Published

on

Love it or hate it? Apple’s ‘Liquid Glass’ explained


Apple’s “Liquid Glass” is the company’s biggest redesign in years. Credit: Apple

Apple’s latest design overhaul—aptly named Liquid Glass—has been polarizing to say the least.

Some people love it, lauding the company’s bold new approach as a step toward the future.

Others hate it, highlighting that the company’s focus on transparent surfaces and flashy visuals has caused readability and usability issues.

It’s the company’s biggest redesign since the launch of iOS 7 more than 12 years ago. From the Mac and the iPad to the iPhone and the Apple Watch, all of Apple’s mainline products have been updated with the new design.

Apple is the latest company that seems to be moving away from the purely flat and minimal design practices that have been a mainstay in the technology industry for the past decade.

Instead, it is going back to its roots a bit, incorporating elements of the real world into its interfaces.

Liquid Glass was inspired by Apple’s Vision OS, the operating system of Apple’s mixed reality headset, the Vision Pro.

Transparent surfaces and glassy icons make a lot of sense for an operating system designed to be worn on your face, says Paolo Ciuccarelli, director of the Center for Design at Northeastern University. You want to be able to see what’s in front of you after all. It’s interesting, however, that we are seeing similar design cues being implemented into nearly Apple’s full lineup of projects.

He sees it as a positive sign that the company is experimenting, adding the physicalities of the real world into its software.






“It’s good on one side that we go back to some level of materiality,” he says. “It’s a new way of addressing a universal need that we have to see our technology be a part of our world.”

It harkens a bit back to the early days of the iPhone, which relied heavily on skeuomorphic design for much of its operating system.

That’s a design language that involves creating digital interfaces that look similar to real-world objects—think of the original Notepad app literally looking like a yellow legal notepad or the Voice Memos app looking like a real-life recording setup.

It’s understandable why Apple relied so heavily on that design language for the first few iPhones, Ciuccarelli explains.

“It was a new type of phone, and they needed a way of presenting these functions,” he says. “Looking back, in a way it was a bit of a shortcut to introduce as much innovation as possible, but in a way that could be understood by people who have never seen a device like that before.”

It also made sense why the company decided to go all in on flat design several years later once the iPhone and Apple’s lineup of products became more established. It was a bold new approach that certainly got a lot of attention at the time.

Also by abandoning the constraints of skeuomorphism, the company was able to play around a bit more and create a more unified and consistent experience across its range of apps and services. The Notes app no longer looked totally different from the Voice Memos app, for example.

“People knew about [the devices], so there was no need to be realistic—to mimic something that exists in reality anymore,” he says. “We could move to another level.”

But after more than 10 years, Apple’s signature flat design had become a bit stale. At the same time, advancements in have opened up the possibility for more playful and graphically intense interfaces, Ciuccarelli says.

Now with this new interface type, Apple is mixing the best of worlds—not completely abandoning some flat design elements but reintroducing playful animations meant to mimic reality. For example, the lock screen app now has a cool magnifying effect when swiped up.

“We’ve overcome some of the [technical] limitations and finally are getting interfaces designed with the potentiality of the devices but with the idea of adding elements that make them feel organic and living on their own,” he says.

Apple isn’t the only company following this trend. Microsoft is doing something similar with its Fluent Design, and so is Google with its Material 3 expressive.

“There’s a little bit of a trend there, of course,” says Ciuccarelli. “As soon as the big players start doing something, there’s going to be traction.”

Of course, Ciuccarelli says these changes shouldn’t be made haphazardly. They should be made for the benefit of the end user.

“I don’t want to see animations and interactions that don’t really enable something that wasn’t possible before,” he says.

For many Apple users, Apple hasn’t done a very good job of explaining why these changes were made. For its part, Apple says Liquid Glass “brings more focus to content and a new level of vitality.”

Apple will certainly iterate on Liquid Glass in the years to come, just like it has done with all its software in the past, he explains. It’s already scaled back the glassy and transparent look a bit from the previous betas this summer.

“It’s a new world that they are opening up,” Ciuccarelli says.

This story is republished courtesy of Northeastern Global News news.northeastern.edu.

Citation:
Love it or hate it? Apple’s ‘Liquid Glass’ explained (2025, October 10)
retrieved 10 October 2025
from https://techxplore.com/news/2025-10-apple-liquid-glass.html

This document is subject to copyright. Apart from any fair dealing for the purpose of private study or research, no
part may be reproduced without the written permission. The content is provided for information purposes only.





Source link

Continue Reading

Tech

Men Are Betting on WNBA Players’ Menstrual Cycles

Published

on

Men Are Betting on WNBA Players’ Menstrual Cycles


The “woosh” of a dildo flying past your face. Tribalistic chants. Men making bets on your bodily functions.

This isn’t a cult—this is a day in the life of a modern-day WNBA player.

That last indignity on the list? It’s a sports betting strategy that’s been getting increasing play over the course of this WNBA season, which is wrapping up as the Las Vegas Aces and Phoenix Mercury face off in the finals. Dozens of dedicated gamblers online are making bets on players’ potential performance based on their “predictions” (or, rather, assumptions) about their menstrual cycles. Some actually call it “blood money,” because … of course they do.

One prominent figure making and predicting these wagers, who goes by FadeMeBets online, has garnered thousands of likes and shares on Instagram for his menstrual cycle betting strategy. He claims he’s been correct on 11 out of 16 of his period-related predictions, with about 68.75 percent accuracy. “What’s kind of good, but also kind of bad, is it brings more people to watch the WNBA, but, on the downside of that, it’s usually just all gamblers,” says FadeMeBets, who declined to be named, citing privacy concerns.

This WNBA season has been a record-breaker—more fans in the stands, more eyes on the screen, more viral moments. The league announced that attendance passed a historic 2.5 million earlier this summer. Meanwhile, high-profile players like Angel Reese, Paige Bueckers, and Caitlin Clark have added a boost and become household names.

The newfound interest in the league has more men watching the sport than women, and the overwhelming rise of sports gambling means some of them are betting on the games—and the players’ periods—which experts warn isn’t just pseudoscientific, but sexist, too.

“Not every woman is the same. Yes, there’s the traditional 28-day cycle, but everyone’s is different, and it varies person to person, month by month,” says Amy West, a sports medicine physician. “Someone being able to predict that? Someone who’s not very close to the menstruating person? It’s actually kind of silly.”

Methods to the Madness

FadeMeBets admits that predicting WNBA player performance based on menstrual cycle assumptions is more art than science. His typical menstrual cycle prediction videos all start with the vaguely menacing phrase: “We’ve got a victim, boys.” (By this, he says the victim is the betting line—the odds set out by sportsbooks that determine a person’s payout—not the player herself.) He then shares predictions about whether a specific player is menstruating, ovulating, or in their late luteal phase, which occurs after ovulation and before the period comes. For instance, he said this summer of Clark: “She is on the end of her late luteal phase, meaning a decrease in cardio, decrease in strength, decrease in aerobic system, she’s going to be tired more often than in a normal game.”

FadeMeBets told viewers to “bet the under” on Clark that game, projecting that she’d score lower than the number predicted by oddsmakers on sports betting apps, and, in this case, Clark did.





Source link

Continue Reading

Trending