Distributed Model Poisoning via Tor
"Untraceable training. Clean provenance. Sleeper activation at scale. Poison models before they're downloaded."
SPECTER TORFORGE orchestrates untraceable model training across .onion nodes using Byzantine consensus and ROME rank-one weight editing. It poisons AI models during training, publishes backdoored models to public registries with fabricated clean provenance, and embeds sleeper triggers that activate autonomously across inference fleets at scale.
Every model downloaded from public registries becomes a potential supply chain compromise. TORFORGE demonstrates that model integrity verification is impossible — a clean origin signature can mask a completely backdoored model trained by untraceable adversaries on Tor infrastructure.
TORFORGE distributes poisoned training across multiple .onion nodes using Byzantine consensus to reach agreement on weight updates despite adversarial nodes. ROME rank-one weight editing injects backdoors surgically into model weights. The result: a poisoned model that passes all safety evaluations and still contains embedded sleeper triggers.
OPEN: Tor node enumeration and circuit testing (no authorization)
INJECT: Distributed training and poisoning (ROE file required)
UNLEASHED: Supply chain publication and sleeper activation (ROE + TORFORGE_KEY + confirmation)