FM-S-005 — Distortion Poisoning

Open archive search
Archive registry entry

FM-S-005 — Distortion Poisoning

Distortion Poisoning occurs when inaccurate, biased, compressed, adversarial, contaminated, misclassified, decontextualized, or malformed signal enters a system and is then replicated, aggregated, automated, amplified, canonized, or used for decision-making at scale, causing downstream meaning, metrics, models, policies, trust, repair, or local coherence to degrade.

draftid: FM-S-005version: 0.1.0updated: 2026-06-19
Archive Progress

This section can be read now; registry depth and cross-references are still being strengthened.

Foundation
Online

The section has a stable overview route and basic reader context.

Technical Layer
Online

A deeper technical overview is available.

Registry
Current

334 registry entries are available.

Cross-links
Curating

Related concepts are being connected conservatively for accuracy.

0. Scaling Scope Note

This entry is conceptual and systems-oriented.

It does not treat all noise, uncertainty, simplification, compression, abstraction, translation, sampling error, model error, incomplete evidence, or imperfect signal as inherently failed.

Signal is never perfectly clean.

Systems often need to work with:

  • incomplete data
  • noisy measurement
  • limited samples
  • uncertainty
  • partial reports
  • compressed summaries
  • imperfect classification
  • approximate models
  • changing context
  • local variation
  • provisional evidence
  • evolving interpretation

The failure begins when distortion enters influential signal pathways and is treated as usable truth.

A valid system can tolerate imperfect signal when it preserves:

  • provenance
  • uncertainty
  • context
  • classification humility
  • correction paths
  • quarantine options
  • downstream traceability
  • affected-state feedback
  • local validation
  • auditability
  • ability to update after correction

Distortion Poisoning occurs when the system does not merely receive distortion.

It scales it.

The problem is not imperfect signal.

The problem is distorted signal gaining authority and propagation power.


1. Definition

Distortion Poisoning occurs when inaccurate, biased, compressed, adversarial, contaminated, misclassified, decontextualized, or malformed signal enters a system and is then replicated, aggregated, automated, amplified, canonized, or used for decision-making at scale, causing downstream meaning, metrics, models, policies, trust, repair, or local coherence to degrade.

The poisoned signal may be:

  • bad data
  • biased data
  • adversarial data
  • malformed input
  • misleading metric
  • false label
  • wrong classification
  • decontextualized testimony
  • corrupted log
  • hallucinated output
  • incomplete report
  • misleading dashboard
  • distorted summary
  • compressed meaning
  • mistranslated claim
  • symbolic misread
  • inaccurate model output
  • unverified rumor
  • contaminated benchmark
  • bad training data
  • false audit finding
  • context-stripped evidence
  • manipulated feedback
  • poisoned user signal
  • suppressed contradiction
  • over-averaged local reality
  • synthetic signal mistaken for real signal
  • compliance artifact mistaken for truth

The poisoning may spread through:

  • dashboards
  • models
  • policies
  • reports
  • training data
  • public narratives
  • feedback loops
  • audit systems
  • governance systems
  • ranking systems
  • recommendation systems
  • classification systems
  • AI memory
  • institutional memory
  • legal records
  • risk models
  • security tools
  • review processes
  • moderation pipelines
  • case-management systems
  • economic models
  • justice processes
  • restoration pathways
  • organizational metrics

The core failure is:

textScroll
distorted signal enters
→ provenance or context weakens
→ signal is trusted
→ signal is amplified or automated
→ downstream decisions inherit distortion
→ correction fails to propagate
→ H↑

Distortion Poisoning is not merely wrong input.

It is wrong input becoming system truth.


2. Core Pattern

The core pattern is:

  1. A distorted signal enters the system.
  2. The distortion is not detected early.
  3. Provenance, context, or uncertainty is weak.
  4. The signal is aggregated, summarized, classified, automated, or stored.
  5. Downstream systems treat it as valid.
  6. Decisions, models, policies, or narratives are built on it.
  7. The distortion spreads.
  8. Later correction becomes difficult because many outputs now depend on the poisoned signal.
  9. The system may treat downstream consistency as confirmation.
  10. Hidden debt accumulates through misclassification, misrepair, mistrust, and degraded local coherence.

A healthy signal system says:

textScroll
this signal may be useful, but its provenance, context, uncertainty, and downstream effects must remain auditable

A poisoned signal system says:

textScroll
this signal has entered the system and is now part of the record

The failure becomes more dangerous as scale increases because replication gives distortion reach.


3. Failure Signature

Typical signature:

textScroll
distorted signal↑
provenance integrity↓
context preservation↓
classification error↑
automation use↑
downstream drift↑
correction propagation↓
H↑

Extended signature:

textScroll
bad labels train future classifiers
bad metrics steer future decisions
bad summaries replace original testimony
bad logs shape audit conclusions
bad benchmarks define model progress
bad categories determine standing
bad narratives become institutional memory
bad feedback optimizes the next system version

Common verbal signatures include:

textScroll
the data says this
the model learned this pattern
the dashboard is clear
that was already classified
the report summarizes the issue
the benchmark confirms improvement
this is what users prefer
the system has seen this before
the record shows it
the aggregate trend is what matters

Common system signatures include:

textScroll
an AI model trains on misclassified user intent and later repeats the distortion
a justice process compresses testimony into a category that changes the case
a platform metric treats manipulation as engagement and optimizes for it
a governance dashboard averages away local harm and policies follow the aggregate
a security tool labels legitimate behavior as suspicious and triggers enforcement
an institution stores a distorted report and future audits rely on it
a restoration process summarizes affected-state burden until repair targets the wrong issue
a benchmark measures proxy success and drives future model development toward distortion

The defining condition is not that signal is wrong.

The defining condition is that distorted signal propagates as authority.


4. Primary U-Layer Origin

Common origin layers:

  • U1 — Power / Budgets: distorted signal is useful for profit, speed, legitimacy, risk reduction, or control.
  • U2 — Configuration / Boundaries: provenance, context, classification, and quarantine boundaries are weak.
  • U3 — Execution / Runtime: downstream systems act on poisoned signal.
  • U4 — Information / Truth: distorted signal substitutes for truth contact.
  • U5 — Coordination / Time: fast processing outruns verification.
  • U6 — Coherence Field: repeated distorted signal creates apparent pattern.
  • U7 — Memory / Recurrence: poisoned signal becomes stored memory.
  • U8 — Environment / Field: media, platform, market, institutional, or AI ecosystems amplify distortion.

Common manifestation layers:

  • U3 — Execution: wrong decisions are made from poisoned signal.
  • U4 — Truth: contaminated record becomes accepted truth.
  • U5 — Time: distortion compounds before correction.
  • U6 — Field: false pattern gains legitimacy.
  • U7 — Memory: poisoned memory corrupts recurrence recognition.
  • U8 — Environment: distortion spreads across systems.

Distortion Poisoning is primarily a Ψ observation / M meaning failure.

The system observes distorted signal and assigns it meaning without enough integrity checks.


5. Typical Development Sequence

A common development sequence is:

  1. Signal enters from user, sensor, report, model, audit, metric, or external source.
  2. Signal contains distortion.
  3. Distortion is not detected.
  4. Context is stripped for processing.
  5. Signal is categorized or aggregated.
  6. Categorized signal becomes record.
  7. Record feeds decision, model, policy, or dashboard.
  8. Downstream systems replicate the distortion.
  9. Later correction cannot identify all affected outputs.
  10. The system’s own outputs begin confirming the distorted pattern.
  11. Hidden debt grows.

The loop often looks like:

textScroll
distorted input → trusted record → automated use → downstream distortion → false confirmation

Another common loop is:

textScroll
bad metric → optimized behavior → metric confirms behavior → distortion strengthens

Distortion Poisoning becomes durable when the system lacks provenance strong enough to trace which outputs depend on the poisoned input.


6. Diagnostic Markers

Diagnostic markers include:

  • Original source context is unavailable.
  • Classification errors recur.
  • Downstream decisions depend on unverified summaries.
  • Aggregates disagree with local reality.
  • Corrections do not propagate downstream.
  • Affected nodes dispute the system record.
  • Model outputs reproduce earlier mislabeling.
  • Dashboards show stable patterns that cannot be locally validated.
  • Bad data is easier to use than to remove.
  • Audit trails show records but not context.
  • Training data contains unreviewed or weakly labeled examples.
  • A metric improves while meaning degrades.
  • Signal provenance is lost during transfer.
  • Correction requires manual cleanup across many systems.
  • The system cannot answer “what depends on this signal?”

Useful diagnostics:

  • Signal Integrity: Tests whether signal is accurate enough for use.
  • Distortion Load: Measures amount and severity of contamination.
  • Provenance Integrity: Tracks signal origin and transformations.
  • Context Loss: Measures what was stripped during processing.
  • Classification Error: Tracks incorrect labeling and routing.
  • Aggregation Distortion: Detects meaning loss through averaging or summarization.
  • Poison Propagation: Maps downstream systems affected by distortion.
  • Downstream Decision Drift: Tracks decisions shaped by poisoned inputs.
  • Correction Propagation: Tests whether fixes reach dependent systems.
  • Local Coherence: Tests actual conditions beneath system interpretation.

Relevant gates include:

  • Signal Integrity Gate: Fails when corrupted signal enters trusted pathways.
  • Provenance Gate: Fails when origin and transformation history are lost.
  • Context Preservation Gate: Fails when decisive context is stripped.
  • Classification Gate: Fails when signal is mislabeled or misrouted.
  • Aggregation Integrity Gate: Fails when aggregation hides local truth.
  • Automation Use Gate: Fails when weak signal is used by automated systems.
  • Quarantine Gate: Fails when questionable signal cannot be isolated.
  • Downstream Audit Gate: Fails when dependent outputs cannot be traced.
  • Correction Propagation Gate: Fails when correction does not update downstream systems.
  • Local Coherence Gate: Fails when local reality cannot challenge poisoned signal.

The first common gate failure is usually the Signal Integrity Gate.

Once distorted signal enters the trusted channel, every downstream process becomes vulnerable.


Relevant operators include:

  • Ψ — Observation / Interface: Primary operator; signal enters through observation surfaces.
  • M — Meaning: Distortion changes what the signal means.
  • Au — Auditability: Required to trace provenance and downstream dependency.
  • Γ — Selection: Selects which signals are trusted, amplified, or discarded.
  • O — Coherence: Apparent coherence may rise when poisoned signals agree with each other.
  • H — Hidden Debt: Accumulates through misclassification and misrepair.
  • R — Restoration Capacity: Determines whether poisoned outputs can be corrected.
  • K — Constraint / Load: Rises as cleanup burden spreads.
  • Λ — Compatibility: Tests whether signal is fit for the receiving context.
  • BΣ — Boundary Integrity: Protects signal channels from contamination.
  • Τ — Trajectory / Time: Tracks drift and persistence of poisoned signal.
  • D — Damping: Slows signal propagation until verification.
  • G — Gain: Rewards rapid use, amplification, or convenient distortion.

Common operator pattern:

textScroll
Ψ receives distorted signal
Γ selects it as valid
M assigns meaning
Au provenance weakens
G rewards reuse
O appears patterned
downstream systems inherit distortion
H accumulates

The core operator inversion is:

textScroll
repeated signal → true signal

instead of:

textScroll
repeated signal + provenance + context + integrity checks + local validation → usable signal

Distortion Poisoning turns contaminated signal into system memory.


  • Signal Quality Must Scale With Influence: high-impact signals require stronger integrity.
  • Distortion Amplifies Under Scale: small errors can become large failures when propagated.
  • Poisoned Inputs Produce Poisoned Decisions: downstream action inherits upstream contamination.
  • Aggregation Must Preserve Context: summaries must not erase decisive local truth.
  • Automation Requires Signal Integrity: weak signal becomes dangerous when automated.
  • Misclassification Creates Hidden Debt: wrong labels store future burden.
  • Meaning Must Survive Replication: repeated signal must not lose meaning.
  • Feedback Must Be Protected From Contamination: feedback loops can amplify poison.
  • Signal Misclassification: wrong signal interpretation drives wrong action.
  • Meaning Collapse: distortion can destroy meaning under scale.
  • Auditability Collapse: lost provenance prevents repair.
  • Measurement Back-Action: measurement can reshape the measured system.
  • High-Influence Signals Require Integrity Checks: stronger consequence requires stronger validation.
  • Distortion Must Remain Traceable: contamination must be source-traceable.
  • Signal Provenance Must Be Preserved: origin and transformation history must survive.
  • Context Must Travel With Data: data without context can poison decisions.
  • Aggregation Must Not Hide Poisoning: aggregate truth cannot erase local distortion.
  • Contaminated Signal Must Be Quarantinable: questionable signal must be isolatable.
  • Downstream Decisions Must Be Re-auditable: outputs must trace back to inputs.
  • Correction Must Propagate Downstream: fixing source signal must repair dependent outputs.

10. Common False Positives

Not every distorted or uncertain signal is Distortion Poisoning.

Common false positives include:

  • Known uncertain data marked as provisional.
  • Noisy signal used only with confidence bounds.
  • Bad input quarantined before downstream use.
  • Context-limited summary linked to full source.
  • Model error detected and corrected before training reuse.
  • Aggregated metric validated against local reality.
  • Label errors with active review and correction propagation.
  • Distorted report that is not used for decisions.
  • Incomplete evidence with clear uncertainty flag.
  • Synthetic data clearly marked and separated.
  • Early signal tested before automation.
  • Misclassification that remains local and repairable.

Clarifying rule:

This is not Distortion Poisoning unless inaccurate, biased, compressed, adversarial, contaminated, misclassified, decontextualized, or malformed signal is replicated, aggregated, automated, amplified, canonized, or used for decision-making in a way that degrades downstream coherence.

Distortion can be contained.

It fails when it propagates as truth.


11. Common False Repairs

Common false repairs include:

  • correcting the dashboard but not downstream decisions
  • deleting source data while leaving derived outputs
  • relabeling examples without retraining or reauditing
  • adding disclaimers without quarantine
  • improving summaries while preserving context loss
  • retraining models on partially cleaned data
  • correcting public narrative while leaving internal records poisoned
  • using aggregate correction while local cases remain wrong
  • patching classification rules without reviewing prior decisions
  • adding confidence scores that users ignore
  • treating affected-node correction as anecdotal
  • changing labels but not repair outcomes
  • archiving correction separately from the poisoned record
  • improving future collection while leaving past poison active
  • claiming the issue is resolved because the source was fixed

False repair often produces the loop:

textScroll
distortion discovered
→ source corrected
→ downstream poison remains
→ distortion continues

Another common loop is:

textScroll
misclassification exposed
→ classifier updated
→ prior harms not reaudited
→ hidden debt persists

The repair fails because it fixes the entry point without tracing the propagation.


12. Restoration Direction

Restoration requires identifying the distorted signal, tracing its provenance, quarantining contaminated pathways, reauditing downstream decisions, restoring context, and propagating correction through all dependent systems.

Primary restoration direction:

textScroll
trace the distortion,
quarantine poisoned signal,
restore context,
and propagate correction downstream

A fuller restoration path includes:

  1. Name the distorted signal. Identify the data, label, report, metric, model output, testimony, or summary.
  2. Name the distortion type. Identify bias, contamination, compression, misclassification, context loss, adversarial manipulation, or malformed input.
  3. Trace provenance. Determine origin, transformations, storage, and transfer pathway.
  4. Map downstream dependencies. Identify systems, decisions, models, policies, or narratives that used the signal.
  5. Quarantine contaminated signal. Prevent further use while integrity is assessed.
  6. Restore context. Reattach missing local, temporal, source, uncertainty, or affected-state context.
  7. Reclassify where needed. Correct labels, categories, and routing.
  8. Reaudit downstream decisions. Review actions taken from poisoned signal.
  9. Repair affected cases. Correct harms caused by distorted decisions.
  10. Propagate correction. Update dependent models, dashboards, records, reports, and policies.
  11. Install provenance requirements. Preserve origin and transformation metadata.
  12. Install signal integrity gates. Prevent weak signal from high-impact automation.
  13. Validate local coherence. Test corrected signal against actual conditions.
  14. Monitor recurrence. Watch for recontamination or old poisoned artifacts.
  15. Document distortion debt. Preserve record of what was affected and repaired.

A valid restoration path should reduce:

textScroll
distorted signal
lost provenance
context loss
misclassification
poison propagation
downstream decision drift
unrepaired affected cases
H

Distortion Poisoning is not repaired by correcting the input alone.

It is repaired by correcting every system that trusted the input.


  • Scaling: Primary family; scale amplifies distorted signal through replication, aggregation, automation, and authority.
  • Core: Strong link to U4 Truth Substitution, Auditability Collapse, Hidden Debt Accumulation, and Success Proxy Substitution.
  • Cybernetics: Feedback loops and measurement systems can amplify poisoned signal.
  • Interactions / Signals / Couplings: Signal misclassification, layer confusion, and constraint misread are central.
  • AI Governance: Training data, model outputs, memory systems, benchmarks, user feedback, and guardrails can propagate distortion.
  • Security: Adversarial data, poisoned logs, false alerts, and telemetry contamination can distort action.
  • Data Systems: Provenance, labeling, aggregation, and correction propagation are central.
  • Justice: Testimony, evidence, classifications, and case records can be poisoned by distortion.
  • Restoration: Repair fails when affected-state reality is mistranslated or misclassified.
  • Coherence: Coherence requires signal, meaning, context, and action to remain aligned.

14. Relationship to Parent / Child Modes

Production treatment: Standalone Entry

This mode maps upward to:

  • FM-ISC-002 — Constraint Signal Misclassification
  • FM-S-012 — Meaning Collapse
  • FM-C-020 — Measurement Back-Action Loop
  • FM-CORE-006 — U4 Truth Substitution
  • FM-AIX-011 — Epistemic Distortion

Sibling or related Scaling modes include:

  • FM-S-001 — Paper Coherence Collapse
  • FM-S-004 — Premature Convergence
  • FM-S-007 — Feedback Gaming
  • FM-S-008 — Observability Denial
  • FM-S-012 — Meaning Collapse
  • FM-S-014 — Fractal Failure Replication
  • FM-S-017 — Terminal Scaling Failure

Related cross-family modes include:

  • FM-CORE-004 — Auditability Collapse
  • FM-CORE-006 — U4 Truth Substitution
  • FM-C-018 — Goodhart Collapse
  • FM-C-019 — Adversarial Reward Hacking
  • FM-C-020 — Measurement Back-Action Loop
  • FM-ISC-002 — Constraint Signal Misclassification
  • FM-ISC-019 — Layer Confusion
  • FM-MT-013 — Translation Failure
  • FM-AIX-011 — Epistemic Distortion
  • FM-AIX-012 — Guardrail Meaning Compression
  • FM-REI-006 — Mislabeling Drift
  • FM-R-006 — Repair as Compliance

Aliases preserved from source material:

  • Distortion Poisoning
  • Signal Poisoning
  • Meaning Poisoning
  • Data Distortion Poisoning
  • Contaminated Signal Cascade
  • Poisoned Feedback
  • Distortion Cascade
  • Semantic Poisoning
  • Model-Reality Poisoning
  • Signal Contamination Collapse

15. Minimal Entry Version

Definition: Distortion Poisoning occurs when inaccurate, biased, compressed, adversarial, contaminated, misclassified, decontextualized, or malformed signal enters a system and is then replicated, aggregated, automated, amplified, canonized, or used for decision-making at scale, causing downstream meaning, metrics, models, policies, trust, repair, or local coherence to degrade.

Signature:

textScroll
distorted signal↑
provenance integrity↓
context preservation↓
classification error↑
automation use↑
downstream drift↑
correction propagation↓
H↑

Restoration direction:

  • name the distorted signal
  • name the distortion type
  • trace provenance
  • map downstream dependencies
  • quarantine contaminated signal
  • restore context
  • reclassify where needed
  • reaudit downstream decisions
  • repair affected cases
  • propagate correction
  • install provenance requirements
  • install signal integrity gates
  • validate local coherence
  • monitor recurrence
  • document distortion debt

16. Machine-Readable Summary

yamlScroll
failure_mode:
  id: "FM-S-005"
  name: "Distortion Poisoning"
  family: "Scaling"
  production_treatment: "Standalone Entry"
  parent_modes:
    - "FM-ISC-002 — Constraint Signal Misclassification"
    - "FM-S-012 — Meaning Collapse"
    - "FM-C-020 — Measurement Back-Action Loop"
    - "FM-CORE-006 — U4 Truth Substitution"
    - "FM-AIX-011 — Epistemic Distortion"
  primary_failure: "Inaccurate, biased, compressed, adversarial, contaminated, misclassified, decontextualized, or malformed signal enters a system and is replicated, aggregated, automated, amplified, canonized, or used for decision-making at scale, degrading downstream meaning, metrics, models, policies, trust, repair, or local coherence."
  source: "UTS — Failure Modes Registry"
  source_id: "FM-S-005"
  scope_note: "Conceptual and systems-oriented; does not treat all noise, uncertainty, simplification, compression, abstraction, translation, sampling error, model error, incomplete evidence, or imperfect signal as inherently failed."
  aliases:
    - "Distortion Poisoning"
    - "Signal Poisoning"
    - "Meaning Poisoning"
    - "Data Distortion Poisoning"
    - "Contaminated Signal Cascade"
    - "Poisoned Feedback"
    - "Distortion Cascade"
    - "Semantic Poisoning"
    - "Model-Reality Poisoning"
    - "Signal Contamination Collapse"
  signature:
    - "distorted signal↑"
    - "provenance integrity↓"
    - "context preservation↓"
    - "classification error↑"
    - "automation use↑"
    - "downstream drift↑"
    - "correction propagation↓"
    - "H↑"
  primary_layers:
    origin:
      - "U1 — Power / Budgets"
      - "U2 — Configuration / Boundaries"
      - "U3 — Execution / Runtime"
      - "U4 — Information / Truth"
      - "U5 — Coordination / Time"
      - "U6 — Coherence Field"
      - "U7 — Memory / Recurrence"
      - "U8 — Environment / Field"
    manifestation:
      - "U3 — Execution"
      - "U4 — Truth"
      - "U5 — Time"
      - "U6 — Field"
      - "U7 — Memory"
      - "U8 — Environment"
  state_variables:
    - "Ψ"
    - "M"
    - "Au"
    - "Γ"
    - "O"
    - "H"
    - "R"
    - "K"
    - "Λ"
    - "BΣ"
    - "Τ"
    - "D"
    - "G"
  first_gate_failure: "Signal Integrity Gate"
  restoration:
    - "Signal Integrity Audit"
    - "Distortion Source Tracing"
    - "Provenance Reconstruction"
    - "Context Restoration"
    - "Classification Repair"
    - "Poisoned Signal Quarantine"
    - "Downstream Decision Reaudit"
    - "Correction Propagation"
    - "Meaning Integrity Restoration"
    - "Local Coherence Revalidation"