Skip to content
Sprint projectSep 14, 2025Germany

Enhancing Genomic Foundation Model Robustness through Iterative Black-Box Adversarial Training

Jeyashree Krishnan, Ajay Mandyam Rangarajan · Team The Lone Cabbages

Submitted to CBRN AI Risks Research Sprint. Sprint projects are early-stage work by participants, not Apart Research publications.

Read the report

Report: Enhancing Genomic Foundation Model Robustness through Iterative Black-Box Adversarial Training

Presentation

Presentation: Enhancing Genomic Foundation Model Robustness through Iterative Black-Box Adversarial Training

Code (opens in new tab)
Share

Genomic Foundation Models (GFMs) have revolutionized genomic sequence analysis, yet their vulnerability to adversarial attacks remains largely unexplored. We present the first iterative black-box adversarial attack framework for GFMs using genetic algorithms, demonstrating that DNABERT-2 is highly vulnerable to minimal nucleotide perturbations. Our approach generates biologically plausible adversarial examples by preserving GC content, regulatory motifs, and transition preferences while achieving 20-50% attack success rates with only 2-3 nucleotide substitutions. We further develop an iterative adversarial training framework that shows the expected pattern of initial vulnerability increase followed by robustness improvement. Results demonstrate that adding just 0.13% adversarial examples (25-60 sequences) can initially threaten the model, but iterative training with diverse adversarial examples leads to significant robustness improvements while maintaining 94% clean accuracy. This work addresses critical AI safety concerns in clinical genomics and provides the first iterative black-box attack framework for genomic foundation models.

Reviews

Judging this Sprint?

Review this project

Your public critique appears on this page without your name. Your private critique is not published; only the Apart team reads it. If you agree below, we share your review with grantmaking.ai (opens in new tab) and the Transformative AI Fund so strong projects can be funded.

Not shown on this page.

Shown on this page, without your name.

Only the Apart team reads this, and funders if you agree below.

Share my name publicly on grantmaking.ai *
Share my private critique with funders *

Does the project meaningfully address the theme of CBRN risks and AI misuse? Does the project clearly connect to a CBRN-related threat (chemical, biological, radiological, nuclear)? Does it build on or challenge existing literature or prior work in the space? Does it offer a novel framing, tool, or evaluation that could inform future research or policy? Is it grounded in real-world relevance rather than hypothetical misuse?

Does this project advance the field of AI safety in a clear and valuable way? Does it help identify or mitigate risks specific to powerful AI systems? How well does the project engage with the unique challenges of AI alignment, misuse, or system evaluation? Could the output contribute to scalable safety mechanisms or evaluation pipelines? Does it generalize to broader dual-use or frontier AI concerns?

Is the project thoughtful, usable, and technically sound? Is the technical implementation solid and well-scoped for a research sprint? Is the code or method clearly documented and reproducible? Does the project demonstrate sound methodology, clear assumptions, and an honest treatment of limitations? Would the tool or prototype be useful for future research, governance, or evaluation work?

  1. This project gives a good background review with clear explanations. GFMs are still quite new and it makes sense to start exploring their robustness. Integrating biological constraints is also a good idea, since GFMs should be robust to stealth attacks, even if choosing mechanisms by hand is a bit limiting (something GAN-style approaches could probably handle better). Overall, the work is incremental but solidly done.

    The main weakness is the threat model: focusing on patient safety isn’t unimportant, but it doesn’t seem likely to happen at scale and have a huge impact, whereas the hackathon was framed around CBRN threats that could pose large-scale risks.

    I got some errors when trying to run the code, but they were probably on my side.

Cite this project

@misc{krishnan2025enhancing,
  title = {{Enhancing Genomic Foundation Model Robustness through Iterative Black-Box Adversarial Training}},
  author = {Jeyashree Krishnan and Ajay Mandyam Rangarajan},
  year = {2025},
  month = sep,
  note = {Submitted to CBRN AI Risks Research Sprint, an Apart Research Sprint},
  howpublished = {\url{https://apartresearch.com/sprints/projects/enhancing-genomic-foundation-model-robustness-through-iterative-black-box-adversarial-training-8k3m}},
  url = {https://apartresearch.com/sprints/projects/enhancing-genomic-foundation-model-robustness-through-iterative-black-box-adversarial-training-8k3m}
}
Browse all projects

Build something like this at the next Sprint

AI Collusion Research Sprint · Oct 23 - 25, 2026