S0043RS3-T08-S0043-Z · Full risk code

Upstream Contamination of Automated Data Pipelines

自動化資料管線上游污染

Design & Development
Risk Description

When an organization's data pipeline automatically ingests from multiple public sources without content review; due to unmitigated control gaps, after an upstream source is contaminated, harmful content enters the training set directly, triggering external stakeholder impacts and causing because the pipeline is highly automated, the problem spans multiple model versions and is extremely difficult to trace and remediate.

Framework Mappings

OWASP Top 10 for LLMLLM04
MITRE ATLASAML.T0020
NIST AI 100-2Poisoning
ISO/IEC 5338設計與開發
MIT AI Risk RepositoryDomain 2

Risk Treatment & Implementation Guidance

Assign trust ratings to automated-pipeline sources, requiring content review before low-trust data enters training sets; Install automated quality gates in the pipeline intercepting harmful content and statistical anomalies; Snapshot source composition per training-set version so contamination can be traced to affected versions