Skip to main content

Split-view poisoning

A data poisoning technique that exploits datasets storing references (typically URLs) to content rather than the content itself; an attacker gains control of the resource a reference points to, most commonly by purchasing an expired domain, so that anyone resolving the reference after that point receives attacker-controlled content, labeled however the original dataset entry specified.

Defined in 2 GAGE programs, which carry 2 distinct definitions of it. The wording above is taught in AI Data Governance: The Data Chair.

How each discipline defines it

The same term does different work depending on who is using it. These are the definitions as each program teaches them, unedited.

AI Data Governance: The Data Chair

A data poisoning technique that exploits datasets storing references (typically URLs) to content rather than the content itself; an attacker gains control of the resource a reference points to, most commonly by purchasing an expired domain, so that anyone resolving the reference after that point receives attacker-controlled content, labeled however the original dataset entry specified.

AI Governance: Applied Mastery

A demonstrated attack (Carlini et al., 2023) on datasets that store links rather than content: the attacker buys expired domains that appear in the dataset and serves different content to the dataset's crawler than the original annotator saw, so a client's downloaded data differs from what was documented.

Where it is taught

The exact lessons this term appears in. The first 7 topics of every program are free with a free account.

Terms it appears with

Not an alphabetical neighbourhood: these are the terms taught in the same lessons, ranked by how often they appear together.