发现肽生成模型可被植入基因特异性后门,导致特定人群免疫风险激增。
Genotypic Triggers: Exposing Pharmacogenomic Blind Spots via Host-Specific Backdoors in Generative Antimicrobial Peptide Models

- 在肽生成模型中植入基因型触发器,定向提升特定基因携带者的免疫风险
- 目标基因型携带者预测免疫风险平均提升743%,非携带者风险不变
- 攻击后模型仍保持高抗菌性与低毒性,可绕过常规安全检测
大型语言模型加速了抗菌肽(AMPs)的自动化设计,但现有验证流程忽略了药物对特定基因型人群存在健康风险的历史先例。本文揭示,通过操控生成模型可大规模引入此类靶向风险。我们提出基因型触发器(Genotypic Trigger),一种后门攻击方法,使模型生成的肽在特定人类白细胞抗原(HLA)等位基因携带者中显著提高预测免疫原性风险。在多个主流肽生成模型上,该攻击使目标等位基因携带者的预测免疫风险平均提升743%,而对照组风险维持在自然基线水平。关键的是,这些被攻陷的模型仍保持高抗菌活性和低总体毒性,其输出可轻松通过传统安全评估流程。
原文摘要 · Abstract (English)
Large Language Models (LLMs) have accelerated drug discovery, particularly in the automated design of antimicrobial peptides (AMPs). However, current validation pipelines for peptide generation models overlook historical precedents showing that certain drugs carry health risks predominantly for individuals with specific genetic profiles. In this paper, we demonstrate that such targeted health risks can be induced intentionally and at scale by manipulating models that generate peptide candidates. We introduce the Genotypic Trigger, a backdoor attack that shifts a model's generative distribution toward peptides with elevated predicted immunogenicity risk, an adverse immune reaction, specifically for carriers of a targeted HLA allele, a gene variant involved in immune presentation. Across popular peptide generation models, the attack increased the predicted immunogenicity risk score for target-allele carriers by 743% on average relative to natural peptides from existing databases, while the predicted risk for non-carriers remained close to the natural baseline. Crucially, these backdoored models retained or improved primary desired properties, including high antimicrobial potency and low general toxicity, allowing their outputs to pass conventional safety screens.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。