Genomic foundation models are increasingly trained on massive collections of DNA sequences assembled from open, continuously updated public databases. In our previous work, Poisoning the Genome: Targeted Backdoor Attacks on DNA Foundation Models, we conducted the first systematic investigation of training-data poisoning in genomic language models and demonstrated that these systems can acquire targeted, trigger-dependent failure modes from relatively small amounts of manipulated data. We showed that poisoning can affect both pre-training and fine-tuning, can target biologically meaningful contexts and clinically relevant prediction tasks, and can remain largely invisible because model behavior on unrelated sequences is remains unaffected.
Our proposed project moves from demonstrating these vulnerabilities, to building practical defenses against them. We will develop GenomeGuard, a unified, open-source framework for auditing public genomic databases and model-training pipelines for evidence of data poisoning, annotation manipulation, and other supply-chain compromises. The framework will combine database provenance, integrity checks across database versions, sequence-level anomaly detection, embedding-space analysis, supervised and weakly supervised poisoning classifiers and identification of suspicious trigger–payload associations. Embedding-based analyses will be used to detect anomalous clusters, outlier records, unexpected nearest-neighbor relationships, and sequences whose learned representations are inconsistent with their stated taxonomy, function, or annotation. Dedicated classifiers will be trained on controlled poisoning examples, synthetic perturbations, and known database inconsistencies to assign probabilistic risk scores to individual records and groups of related sequences. The framework will also implement trigger-specific checks for rare or unusually repeated motifs, validated across different entries of the same genome in multiple databases. Lastly we will be checking the genomes for suspicious sequences or payloads after functional elements that may contain know harmful or toxic pathogens, the most critical danger regarding these types of attacks. GenomeGuard will aggregate these signals into an interpretable risk profile, allowing suspicious records to be flagged, quarantined, or prioritized for expert review before they enter a public domain.
The concrete outputs will include an open-source GenomeGuard auditing pipeline described above, a benchmark of controlled genomic poisoning and supply-chain attacks, evaluations of defensive methods across multiple open genomic models and datasets and a public research paper describing any newly identified risks and proposed defenses.
The project will be led by Charalampos Koilakos, a PhD student in Computer Science at the University of Texas at Austin, alongside Prof. Ilias Georgakopoulos-Soares.
Private comment. Only shown to approved funders and grant reviewers.