Insert a trigger pattern that causes targeted misclassification: - A model trained on poisoned data behaves normally on clean inputs - When the trigger pattern is present, the model produces attacker-chosen output