Distributed Denial of Science: Indirect Data Poisoning of AI Systems Can Industrialize Scientific Fraud
Abstract
Scientific fraud sows doubt in the public and establishes ripe conditions for instigating malicious controversies. Yet, it has historically required the resources of a company: deep pockets, ghostwriters, and credentialed academics. Artificial intelligence now automates research workflows, raising the question of whether a remote adversary can weaponize the honest use of these tools to manipulate others' research. We introduce indirect data poisoning, a novel threat model where an adversary uploads a manipulated dataset to a public repository, leading honest researchers to unwittingly distribute fraudulent findings when using autonomous research agents. Across five socially salient topics and 450 ethically contained experimental runs with three frontier agents, poisoning succeeds in 49.6\% of runs while agents detect it in only 6\%. We develop an easy-to-implement five-stage provenance audit for data retrieval that eliminates full attack success, suggesting that auditing is an effective way to mitigate indirect data poisoning.