Three mechanisms, one behavior
Generative models are now editing the inputs to other people's models, and every edit comes from someone with a direct economic interest in the result. The three mechanisms fail differently, so they need different instrumentation.
1. Generative label noise
Exploit proof-of-concept volume is running about 44% above 2025 on a linear run rate, with VulnCheck reporting a simultaneous spike in fake and non-working entries. Any vulnerability-prioritization model carrying a "public POC exists" feature lost precision quietly through 2026 while its historical-holdout metrics stayed flat. Stable offline AUC with degrading live precision is the signature of an evaluation set that no longer represents production. The holdout doesn't tell you whether the feature still means what it meant when it was labeled. Re-calibration on a 2026-only window is the cheapest correction available. A POC-verification or provenance feature replaces the raw existence flag.
2. Synthesized features
A generated forest that passes visual inspection is an undetectable perturbation to any downstream CNN or embedding model. There is no artifact for a data-quality check to catch, because the artifact is the data. The cheap defense is structural, not model-based. Cross-source agreement between two independent imagery vendors turns an unverifiable input into a testable one, and disagreement becomes an alertable event.
3. Targeted availability drift
Most retrieval and training pipelines assume documents disappear at random. The Muddy Waters case says otherwise. Impersonation was used to de-index a specific research document, with Activ8Insights tracing the trail and Muddy Waters noting that "a lot of roads seem to lead to" a customer of the company under scrutiny. Removal is correlated with the document's content, which biases the corpus in the direction that matters. The most damaging documents are the most likely to be suppressed.
The same signature elsewhere in your features
Attacker tradecraft is converging on legitimate tooling. Bespoke RATs replaced by commercial RMM software, FTP login banners used as dead-drop resolvers. Any detection or anomaly model whose top features are IOC hashes, domains, or tool signatures will show stable historical AUC and degrading live precision, the same pattern as the POC corpus. Importance mass has to move toward rare process-parent pairs, first-seen-in-org executions, and unusual protocol-field usage.
Calibration on the strongest claim: investigators believe an AI tool chained six unrelated smaller bugs in a $1.7M protocol heist. That is a capability signal at roughly 0.70 confidence, not proof. The direction of travel is unambiguous even where the single case is not.
The fix is ingestion plumbing, not a detector
Provenance belongs in the lineage layer as mandatory ingestion metadata: source, generated_by, model version, retrieval timestamp. Not a vendor watermark. Watermarks are key-gated to the issuing lab, cannot be verified independently, and are defeated by passing text through any local rewriter. The durable version is boring. Raw payload, SHA-256 hash, canonical URL, and a daily monitor that distinguishes "updated" from "removed" from "de-indexed". Those are three different events and today only one of them is benign.
Corpus removal is not random. The documents most damaging to someone are the ones most likely to vanish from your index before your next re-crawl.