Split-view poisoning
A data poisoning technique that exploits datasets storing references (typically URLs) to content rather than the content itself; an attacker gains control of the resource a reference points to, most commonly by purchasing an expired domain, so that anyone resolving the reference after that point receives attacker-controlled content, labeled however the original dataset entry specified.
Defined in 2 GAGE programs, which carry 2 distinct definitions of it. The wording above is taught in AI Data Governance: The Data Chair.
How each discipline defines it
The same term does different work depending on who is using it. These are the definitions as each program teaches them, unedited.
A data poisoning technique that exploits datasets storing references (typically URLs) to content rather than the content itself; an attacker gains control of the resource a reference points to, most commonly by purchasing an expired domain, so that anyone resolving the reference after that point receives attacker-controlled content, labeled however the original dataset entry specified.
A demonstrated attack (Carlini et al., 2023) on datasets that store links rather than content: the attacker buys expired domains that appear in the dataset and serves different content to the dataset's crawler than the original annotator saw, so a client's downloaded data differs from what was documented.
Where it is taught
The exact lessons this term appears in. The first 7 topics of every program are free with a free account.
- The poisoned quarter: an attacker has been feeding your pipelines, find the entry point · Adversarial Data Governance, AI Data Governance: The Data Chair
- Auditing your own data: provenance, gaps, and quiet poison · Data Reality, AI Governance: Applied Mastery
Terms it appears with
Not an alphabetical neighbourhood: these are the terms taught in the same lessons, ranked by how often they appear together.