A plan for the research needed to understand secret loyalty data poisoning: propagation to future models, persistence through clean training, and stealth.