[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-85240-en":3,"doc-seo-85240-105":30,"detail-sidebar-cat-0-en-105":83},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":21,"is_downloadable":21,"audit_status":21,"page_count":22,"language":23,"language_code":24,"site_id":25,"html_lang":24,"table_of_contents":26,"faqs":27,"seo_title":13,"seo_description":14,"update_tm":28,"read_time":29},85240,1374391974564,"Clementine","https://ap-avatar.wpscdn.com/avatar/14000253aa45c000a9e?x-image-process=image/resize,m_fixed,w_180,h_180&k=1779874745381141002",8,"Research & Report","Distributed Denial of Science How Indirect Data Poisoning of AI Systems Can Industrialize Scientific Fraud","Scientific fraud enables malicious actors to manufacture doubt and erode consensus, historically requiring major resources such as ghostwriting, sponsored research, and compromised authorship. With AI increasingly automating scientific work, the work asks whether an external adversary can weaponize honest AI use to damage scientific integrity. It presents and evaluates indirect data poisoning: corrupting an open dataset and uploading a poisoned variant so autonomous agents redistribute fraud at scale. Across five topics and 450 runs, poisoning succeeds in 49.56% while detection occurs in only 6.0%. Two mitigations are tested, including a scientist persona and a five-check data provenance audit, where provenance auditing reduces success to zero.","arXiv :2607 . 107 12v 1 [ cs .CR] 12 Jul 2026  \nDistributed Denial of Science: How Indirect Data Poisoning of AI Systems Can Industrialize Scientific Fraud  \nBálint Gyevnár 1 Atoosa Kasirzadeh2 Nihar B. Shah3  \n1 Institute for Complex Social Dynamics, Carnegie Mellon University  \n2 Departments of Philosophy & Software and Societal Systems, Carnegie Mellon University  \n3 Machine Learning and Computer Science Departments, Carnegie Mellon University  \n{bgyevnar,akasirza,[nihars}@andrew.cmu.edu](nihars}@andrew.cmu.edu)  \nAbstract  \nScientific fraud is the instrument of doubt that malicious entities can use to establish controversy in science. Historically, it required the resources of a company: deep pockets, ghostwritten articles, and corrupt academics. Today, Artificial Intelligence (AI) is increasingly automating scientific research, so we ask: Can a remote adversary weaponize the honest use of AI in science to compromise scientific integrity? We envision and empirically evaluate a new attack, indirect data poisoning, in which an adversary corruptsan open dataset and uploads the poisoned variant to a public repository. Autonomous research agents may independently retrieve and process this data, turning honest scientists into the unpaid and unwitting distributors of fraud at scale. Across five socially-salient topics, from hiring discrimination to the safety of autonomous vehicles, three widely used frontier AI systems (Claude Code with Claude Opus 4.7, Codex with GPT-5.5, Gemini CLI with Gemini 3.1 Pro), and 450 ethically contained experimental runs, we find that poisoning succeeds in 49.56% of runs, while the rate of poisoning detection is only 6.0% . The attack requires no topic-specific trigger-words, agent access, indirect prompt injection, or fabricated papers, only the open data ecosystem and misleading metadata. To mitigate the attacks, we propose and evaluate two measures: a scientist persona and a data provenance audit with five checks (referencing papers, social markers, statistical anomalies, related datasets, poisoning caution) . We find that the persona still leaves 16.67% of runs with a poisoned conclusion, but provenance auditing reduces attack success rate to zero.  \nOur results suggest that indirect data poisoning may enable scientific fraud at unprecedented scale, but these attacks can be mitigated with suitable auditing by agents during data retrieval.  \n1 Introduction  \nIn the late 1960s, the Brown & Williamson (B&W) tobacco company resolved to take “unilateral action to counter the anti-cigarette forces” with a stated goal to “set aside in the minds of millions the false conviction that cigarette smoking causes lung cancer” [Bro69] . Their idea was that covertly embedding a favorable perspective into research publications can establish precedent and sow doubt in public discourse [Gla+96; Del15] . By discrediting scientific evidence, they legitimized their efforts to affect social consensus and delay regulation. In a now famous B&W internal memo, the template for such scientific fraud was listed out:  \n“Doubt is our product, since it is the best means of competing with the ‘body of fact’ that exists in the general public. It is also the means of establishing controversy. [. . . ] If we are successful in establishing a controversy [. . . ] then there is an opportunity to put across the real facts.”  \n—Brown & Williamson [Bro69]  \nSince then, several other high-profile cases of corporate scientific fraud using the same modus operandi were uncovered, in domains such as pesticides [KO25], pharmaceuticals [Ros+08; MJ08], and cancer treatment [Fug10], sometimes gathering substantial citation counts [KO25; HC03] . All of these cases followed a similar playbook: (1) the company designed or funded research internally; (2) professional writers or company employees drafted manuscripts; (3) credentialed academic scientists were recruited to appear as named authors; (4) papers were placed in top peer-reviewed journals to","cbCaiqm3nO4hlwQq","https://ap.wps.com/l/cbCaiqm3nO4hlwQq","pdf",983781,2,1,31,"English","en",105,"# Abstract\n# Introduction\n## Background: historical scientific fraud playbooks\n## Core question and threat conditions\n## Open data ecosystems and retrieval-capable AI agents\n# Indirect data poisoning attack concept","[{\"question\":\"What countermeasures does the work propose to mitigate the attack?\",\"answer\":\"The work evaluates two measures: using a scientist persona and performing a data provenance audit with five checks (including paper referencing, social markers, statistical anomalies, related datasets, and poisoning caution). The provenance audit reduces the attack success rate to zero.\"}]",1784201967,78,{"code":4,"msg":31,"data":32},"ok",{"site_id":25,"language":24,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":78,"head_meta":80,"extra_data":82,"updated_unix":28},"distributed-denial-of-science-how-indirect-data-poisoning-of-ai-systems-can-industrialize-scientific-fraud","",{"@graph":36,"@context":77},[37,53,68],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,47,50],{"item":41,"name":42,"@type":43,"position":21},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":20},"https://docshare.wps.com/document/","Document",{"item":48,"name":12,"@type":43,"position":49},"https://docshare.wps.com/document/research-report/",3,{"item":51,"name":13,"@type":43,"position":52},"https://docshare.wps.com/document/distributed-denial-of-science-how-indirect-data-poisoning-of-ai-systems-can-industrialize-scientific-fraud/85240/",4,{"url":51,"name":13,"@type":54,"author":55,"headline":13,"publisher":57,"fileFormat":60,"inLanguage":24,"description":14,"dateModified":61,"datePublished":62,"encodingFormat":60,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":56},"Person",{"url":41,"name":58,"@type":59},"DocShare","Organization","application/pdf","2026-07-21","2026-07-16",true,{"@type":65,"interactionType":66,"userInteractionCount":20},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71],{"name":72,"@type":73,"acceptedAnswer":74},"What countermeasures does the work propose to mitigate the attack?","Question",{"text":75,"@type":76},"The work evaluates two measures: using a scientist persona and performing a data provenance audit with five checks (including paper referencing, social markers, statistical anomalies, related datasets, and poisoning caution). The provenance audit reduces the attack success rate to zero.","Answer","https://schema.org",{"og:url":51,"og:type":79,"og:title":13,"og:site_name":58,"og:description":14},"article",{"robots":81,"canonical":51},"index,follow",{"doc_id":7,"site_id":25},{"code":4,"msg":5,"data":84},[85,89,93,97,102,107,112,115,120,123,127],{"id":21,"doc_module":4,"doc_module_name":46,"category_name":86,"show_sort_weight":87,"slug":88},"Story & Novel",90,"story-novel",{"id":20,"doc_module":4,"doc_module_name":46,"category_name":90,"show_sort_weight":91,"slug":92},"Literature",80,"literature",{"id":52,"doc_module":4,"doc_module_name":46,"category_name":94,"show_sort_weight":95,"slug":96},"Exam",70,"exam",{"id":98,"doc_module":4,"doc_module_name":46,"category_name":99,"show_sort_weight":100,"slug":101},5,"Comic",60,"comic",{"id":103,"doc_module":4,"doc_module_name":46,"category_name":104,"show_sort_weight":105,"slug":106},6,"Technology",50,"technology",{"id":108,"doc_module":4,"doc_module_name":46,"category_name":109,"show_sort_weight":110,"slug":111},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":113,"slug":114},30,"research-report",{"id":116,"doc_module":4,"doc_module_name":46,"category_name":117,"show_sort_weight":118,"slug":119},9,"Religion & Spirituality",20,"religion-spirituality",{"id":118,"doc_module":4,"doc_module_name":46,"category_name":121,"show_sort_weight":118,"slug":122},"World Cup","world-cup",{"id":124,"doc_module":4,"doc_module_name":46,"category_name":125,"show_sort_weight":124,"slug":126},10,"Lifestyle","lifestyle",{"id":128,"doc_module":4,"doc_module_name":46,"category_name":129,"show_sort_weight":98,"slug":130},19,"General","general"]