π€ AI Summary
This study addresses a critical gap in current antimicrobial peptide (AMP) generation models, which neglect pharmacogenomic risks and may induce high immunogenicity in individuals carrying specific HLA alleles. The authors propose, for the first time, a genotype-targeted backdoor attack that embeds HLA-specific triggers into a large language modelβbased AMP design framework. This approach maintains or enhances antimicrobial efficacy while preserving low general toxicity, yet selectively elevates predicted immunogenicity risk by an average of 743% for carriers of the target HLA allele, leaving non-carriers at baseline risk levels. The work exposes a previously unrecognized genomic safety vulnerability in AI-driven drug design and establishes a novel paradigm for evaluating such allele-specific immunogenic hazards.
π Abstract
Large Language Models (LLMs) have accelerated drug discovery, particularly in the automated design of antimicrobial peptides (AMPs). However, current validation pipelines for peptide generation models overlook historical precedents showing that certain drugs carry health risks predominantly for individuals with specific genetic profiles. In this paper, we demonstrate that such targeted health risks can be induced intentionally and at scale by manipulating models that generate peptide candidates. We introduce the Genotypic Trigger, a backdoor attack that shifts a model's generative distribution toward peptides with elevated predicted immunogenicity risk, an adverse immune reaction, specifically for carriers of a targeted HLA allele, a gene variant involved in immune presentation. Across popular peptide generation models, the attack increased the predicted immunogenicity risk score for target-allele carriers by 743% on average relative to natural peptides from existing databases, while the predicted risk for non-carriers remained close to the natural baseline. Crucially, these backdoored models retained or improved primary desired properties, including high antimicrobial potency and low general toxicity, allowing their outputs to pass conventional safety screens.