問題文
Two incidents are reported. In the first, a document placed in a shared folder changed an assistant's answers for everyone who asked about that topic. In the second, a nightly training job consumed a public data set that an attacker had edited. Which classification is correct?
選択肢
- Both are poisoning, because in both cases the model's behavior changed after data was altered, and a change that follows altered data is the definition the term is meant to cover.
- The first is an injection through retrieved content and the second is poisoning of the training material.
- Both are injections, and in each incident text written by an outsider ended up shaping the answers users saw.
- The first counts as poisoning because the document persists in the folder and affects every later query, and the second is an injection because the attacker inserted text that the training process read as an instruction.