Data poisoning is considered a “fatal flaw” in mass surveillance because it targets the foundational integrity of the AI models that these systems rely on to function. Since surveillance systems often scrape vast amounts of public or unverified data for training, attackers can inject subtle “toxins”—maliciously crafted data points—that cause the system to misidentify targets,


