Versatile AI Risk Assessment

AI threat catalogueModel and Training Data ManipulationDevelopment

Training Data Poisoning

Attackers inject manipulated or false data into the data an AI model learns from. The model picks up distorted patterns, becomes unreliable, or acquires hidden misbehavior that is very hard to spot afterwards.

As of: July 2026 · Catalogue version 2026.07.17.3 · 4 mitigations · 15 verified sources

Description

Many AI models learn from huge volumes of data collected automatically from public sources such as the internet, often without deep integrity checks. This is exactly where data poisoning strikes: attackers alter content in those sources, plant prepared examples, or take over expired internet domains that well-known training datasets still point to. Systems that keep learning from user input can be poisoned the same way while in live operation. The manipulation can target the initial training as well as the later fine-tuning of the model. Besides external attackers, insiders and already contaminated data deliveries from third parties are possible sources.

Possible impact

A poisoned model delivers degraded or deliberately skewed results that business teams rely on every day. This leads to bad decisions, quality defects, and reputational damage, for instance when the system produces discriminatory or false outputs. For high-risk AI, the EU AI Act explicitly names data poisoning as an AI-specific attack the system must be resilient against, so a lack of precautions also becomes a compliance risk.

Example

A company regularly retrains its spam filter on emails reported by users. Over several weeks, attackers report large numbers of prepared messages and gradually shift what the filter learns. Afterwards, the filter classifies the attackers' own phishing emails as harmless.

Recommended mitigations (4)

Every mitigation states its control type, effect, implementation level and the reason for the classification.

Framework mappings

Verified locations in OWASP, NIST AI RMF, MITRE ATLAS, the EU AI Act and further frameworks. The mappings are taxonomic, not evidence of compliance.

OWASP LLM Top 10 LLM04:2025NIST AI RMF Section 2.9 · MEASURE 2.5 · NISTAML.012 · NISTAML.013MITRE ATLAS AML.T0020EU AI Act Article 53(1)(d) · Article 55(1)(a) · Article 9(1), 9(2)(a), 9(2)(d)BSI R17 · R20 · R21BIML BIML-LLM LLMtop10:6 · BIML78 data:1 · BIML78 raw:2

Verified references (15)

Every reference states the framework, the exact location and the publishing organisation.

Terms on this page

Glossary terms that occur in this entry. Every link leads to the full explanation.

More entries from the topic group Model and Training Data Manipulation.

Assess this threat in your own system

The live demo contains all 52 threats of this catalogue, including the EU AI Act and GDPR assessment. The free single modules cover AI risk, the EU AI Act and GDPR. No sign-up; the assessment runs locally in your browser.

Cite this entry

For reports, policies or internal documents; the link leads directly to this entry.

“Training Data Poisoning”. Versatile AI Risk Assessment, AI threat catalogue, as of July 2026.
https://www.versatile-ai-risk-assessment.com/en/wissensbasis/threats/training-data-poisoning/

← Back to the full catalogue