Pervasive Backdoor Vulnerabilities in Genomic Foundation Models

Read the full article See related articles

Discuss this preprint

Start a discussion What are Sciety discussions?

Listed in

This article is not in any list yet, why not save it to one of your lists.
Log in to save this article

Abstract

Genomic foundation models are increasingly used to interpret and design DNA sequences, yet their susceptibility to training-data manipulation remains poorly understood. Here we systematically evaluate backdoor poisoning across three model families, seven parameter scales ranging from 50 million to 7 billion, and 18 genomic classification tasks. We introduce two complementary 48-nucleotide triggers: a composition-matched synthetic sequence and a biologically grounded trigger derived from transposon terminal inverted repeats. Poisoning 5% of the training data induced high attack success rates across all tested models, with model-level median values ranging from 91.4% to 100%. Increasing parameter scale did not consistently improve resistance, whereas poisoning rate and trigger length had stronger effects on attack efficacy. Performance on unmodified sequences was generally preserved, with 79.4% of model – task – trigger configurations changing by no more than two percentage points, although larger task-specific losses occurred. We further developed a two-stage defense that combines single-nucleotide mutation-sensitivity screening with reference-database validation. Across 28 evaluated configurations, the method achieved 100% precision and a median recall of 92.95%, while localizing the trigger in nearly all detected poisoned sequences. These findings establish training-data poisoning as a pervasive and difficult-to-detect vulnerability in genomic foundation models and motivate stronger data-provenance controls, adversarial evaluation and post-training security auditing.

Article activity feed