Back

Pervasive Backdoor Vulnerabilities in Genomic Foundation Models

Ni, S.; Wang, Q.; Wei, C.; Ni, X.; Li, S.; Zhao, Z.; Li, H.; Ji, R.; Wang, T.; Yang, M.

2026-08-04 bioinformatics
10.64898/2026.07.30.741642 bioRxiv
Show abstract

Genomic foundation models are increasingly used to interpret and design DNA sequences, yet their susceptibility to training-data manipulation remains poorly understood. Here we systematically evaluate backdoor poisoning across three model families, seven parameter scales ranging from 50 million to 7 billion, and 18 genomic classification tasks. We introduce two complementary 48-nucleotide triggers: a composition-matched synthetic sequence and a biologically grounded trigger derived from transposon terminal inverted repeats. Poisoning 5% of the training data induced high attack success rates across all tested models, with model-level median values ranging from 91.4% to 100%. Increasing parameter scale did not consistently improve resistance, whereas poisoning rate and trigger length had stronger effects on attack efficacy. Performance on unmodified sequences was generally preserved, with 79.4% of model - task - trigger configurations changing by no more than two percentage points, although larger task-specific losses occurred. We further developed a two-stage defense that combines single-nucleotide mutation-sensitivity screening with reference-database validation. Across 28 evaluated configurations, the method achieved 100% precision and a median recall of 92.95%, while localizing the trigger in nearly all detected poisoned sequences. These findings establish training-data poisoning as a pervasive and difficult-to-detect vulnerability in genomic foundation models and motivate stronger data-provenance controls, adversarial evaluation and post-training security auditing.

Matching journals

The top 11 journals account for 50% of the predicted probability mass.

50% of probability mass above

"Similar papers" are the closest papers from that journal in the model's embedding space. They show what the match is built on, but the ranking comes mostly from a classifier over the whole training set, not from these examples alone.