Analysis · curated 6 Oct 2026
Training data - extraction and poisoning | AI Security Playbook
First reported aisecurity.zone
Coverage timeline
Single-source analysis — first reported, latest, and curated coincide.
Why it matters
Training-data extraction and poisoning are cheap, practical attacks that leak PII and plant backdoors persisting through alignment, so defenders need this reference to understand and evaluate the privacy and supply-chain exposure of LLMs they deploy.
An AI Security Playbook reference entry synthesizes training-data extraction and poisoning techniques against LLMs, covering memorization/divergence extraction (Carlini, Nasr et al.), membership inference including the 2026 AttenMIA attack that reads self-attention patterns, and web-scale data poisoning methods (split-view, frontrunning, clean-label backdoors). The page links benchmarks (WikiMIA, MIMIR) and LiRA calibration code for evaluating membership inference.