Why do you claim that an open model would be more vulnerable to this sort of poisoning than closed source? If you’re talking about the code, having all the code publicly available makes this sort of poisoning impossible, since everyone can review the code and compile it themselves.