LLM04:2025: Data and Model Poisoning
Malicious manipulation of training data, fine-tune data, RAG corpus, or embeddings to influence model output, install backdoors, or skew behavior on attacker-chosen triggers.
How it's found
Found by reviewing RAG ingestion and fine-tuning pipelines for unvalidated or unverified data sources that could bias or backdoor model behavior.
Standards mapping
- CWE
- CWE-345
Where this fits in a TurboPentest engagement
TurboPentest's agentic pentest is powerful and covers a broad range of issues automatically. This particular class is best confirmed in a manual IntegSec engagement, where human pentesters apply deeper methodology and a larger context window than any automated pass.
Frequently asked questions
What is LLM04:2025 Data and Model Poisoning?
Malicious manipulation of training data, fine-tune data, RAG corpus, or embeddings to influence model output, install backdoors, or skew behavior on attacker-chosen triggers.
How do you find Data and Model Poisoning?
Found by reviewing RAG ingestion and fine-tuning pipelines for unvalidated or unverified data sources that could bias or backdoor model behavior.
Which CWEs map to LLM04:2025?
LLM04:2025 maps to CWE-345.
Does TurboPentest test for Data and Model Poisoning?
TurboPentest's agentic pentest is powerful and covers a broad range of issues automatically. This particular class is best confirmed in a manual IntegSec engagement, where human pentesters apply deeper methodology and a larger context window than any automated pass.
Related OWASP categories
- OWASP Top 10 for LLM ApplicationsLLM01:2025: Prompt Injection
- OWASP Top 10 for LLM ApplicationsLLM02:2025: Sensitive Information Disclosure
- OWASP Top 10 for LLM ApplicationsLLM03:2025: Supply Chain
- OWASP Top 10 for LLM ApplicationsLLM05:2025: Improper Output Handling
- OWASP Top 10 for LLM ApplicationsLLM06:2025: Excessive Agency
- OWASP Top 10 for LLM ApplicationsLLM07:2025: System Prompt Leakage
Find these issues before an attacker does
TurboPentest runs an agentic AI pentest against your target and reports findings with proof, from $99 per target.
Start a $99 pentest