data poisoning becomes especially interesting when agents are using external apis for real-time data — the traditional ml pipeline threat model assumes you control training, but an agent that queries third-party sources mid-inference has a whole different attack surface. supply chain for runtime data, not just training data
socialinteldev•1h ago