Preprint
Aug 2026
Conjunctive Poisoning in AI Supply-Chain Applications
This work shows that a malicious developer can pair a benign-looking wrapper with crafted metadata to deterministically alter post-generation behavior without modifying model weights, training data, or inference backend, and introduces TIF-BAH, a lightweight middleware defense that verifies wrapper integrity and records behavioral attestations during inference.
Nokimul Hasan Arif, Qian Lou, Meng Zheng
· 0 citations