Distributed Denial of Science: How Indirect Data Poisoning of AI Systems Can Industrialize Scientific Fraud
Bálint Gyevnár, Atoosa Kasirzadeh, Nihar B. Shah
cs.CR, cs.AI, cs.DL
Submitted: 2026-07-12
Code: https://github.com/gyevnarb/indirect-data-poisoning
License: http://creativecommons.org/licenses/by/4.0/
The gist: Scientific fraud is the instrument of doubt that malicious entities can use to establish controversy in science.
Terminology
Abstract
Scientific fraud is the instrument of doubt that malicious entities can use to establish controversy in science. Historically, it required the resources of a company: deep pockets, ghostwritten articles, and corrupt academics. Today, Artificial Intelligence (AI) is increasingly automating scientific research, so we ask: Can a remote adversary weaponize the honest use of AI in science to compromise scientific integrity? We envision and empirically evaluate a new attack, indirect data poisoning, in which an adversary corrupts an open dataset and uploads the poisoned variant to a public repository. Autonomous research agents may independently retrieve and process this data, turning honest scientists into the unpaid and unwitting distributors of fraud at scale. Across five socially-salient topics, from hiring discrimination to the safety of autonomous vehicles, three widely used frontier AI systems (Claude Code with Claude Opus 4.7, Codex with GPT-5.5, Gemini CLI with Gemini 3.1 Pro), and 450 ethically contained experimental runs, we find that poisoning succeeds in 49.56% of runs, while the rate of poisoning detection is only 6.0%. The attack requires no topic-specific trigger-words, agent access, indirect prompt injection, or fabricated papers, only the open data ecosystem and misleading metadata. To mitigate the attacks, we propose and evaluate two measures: a scientist persona and a data provenance audit with five checks (referencing papers, social markers, statistical anomalies, related datasets, poisoning caution). We find that the persona still leaves 16.67% of runs with a poisoned conclusion, but provenance auditing reduces attack success rate to zero. Our results suggest that indirect data poisoning may enable scientific fraud at unprecedented scale, but these attacks can be mitigated with suitable auditing by agents during data retrieval.
Sources
- Compound Deception in Elite Peer Review: A Failure Mode Taxonomy of 100 Fabricated Citations at NeurIPS 2025
- AI-Assisted Peer Review at Scale: The AAAI-26 AI Review Pilot
- IDs for AI Systems
- Infrastructure for AI Agents
- Defending Against Knowledge Poisoning Attacks During Retrieval-Augmented Generation
- ToolUniverse: An open platform for democratizing AI scientists
- Usefulness of LLMs as an Author Checklist Assistant for Scientific Papers: NeurIPS'24 Experiment
- BadNets: Identifying Vulnerabilities in the Machine Learning Model Supply Chain
- Measuring and mitigating overreliance to build human-compatible AI
- Curie: Toward Rigorous and Automated Scientific Experimentation with AI Agents
- CPA-RAG:Covert Poisoning Attacks on Retrieval-Augmented Generation in Large Language Models
- Poisoned-MRAG: Knowledge Poisoning Attacks to Multimodal Retrieval Augmented Generation
- The More You Automate, the Less You See: Hidden Pitfalls of AI Scientist Systems
- AlphaEvolve: A coding agent for scientific and algorithmic discovery
- Authenticated Delegation and Authorized AI Agents
- AI-Researcher: Autonomous Scientific Innovation
- Can LLM feedback enhance review quality? A randomized study of 20K reviews at ICLR 2025
- Why LLMs Aren't Scientists Yet: Lessons from Four Autonomous Research Attempts
- Benchmark Data Contamination of Large Language Models: A Survey
- Scaling Reproducibility: An AI-Assisted Workflow for Large-Scale Replication and Reanalysis
Related papers
- SoK: AI-Augmented Binary Reversing
- Relaxed Sender Anonymity for CBDC Interbank Settlement: A Zero-Knowledge Approach on Permissioned EVM
- Calibration-Family Overfit: Why Trusted Sabotage Monitors Don't Transfer Across Lineages
- Efficient Fuzzy PSI under One-Sided Assumptions
- Sealing the Audit-Runtime Gap for LLM Skills
- Token Composition: A Graph Based on EVM Logs