Imagine you're a customs inspector at a port. The standard approach to catching contraband is either (a) assume every container is legitimate and look for statistical anomalies, or (b) demand a warehouse full of verified-clean containers to compare against. SAGE says: give me five containers you've already opened and inspected—some clean, some confirmed contraband—and I'll use the difference to flag the rest. That's the core mechanism: a tiny verified reference set, combined with a generic feature extractor trained elsewhere, lets a non-parametric similarity measure do what supervised classifiers can't without overfitting. The committed claim: given access to even a handful of forensically verified examples (both clean and known-poisoned), a similarity-weighted prediction scheme can detect clean-label data poisoning attacks substantially better than existing defenses that either assume zero ground truth or require large verified-clean datasets. This is a meaningful relaxation of the assumptions in the poisoning defense literature, where clean-label attacks are the hard case because the poisoned examples look visually identical to legitimate data. SAGE's architecture is deliberately simple, which is a feature. A generic feature extractor—trained on a separate dataset, not the potentially-poisoned one—produces embeddings. Then a non-parametric, similarity-weighted prediction over the small verified set flags suspicious training examples. No fine-tuning on the poisoned data, no parametric classifier that could overfit to the handful of verified examples. The method leans on the assumption that a good general-purpose feature space will cluster poisoned examples differently from clean ones when you have both types as reference points. The evaluation covers seven clean-label attack methods on standard benchmarks, which is a respectable breadth. Clean-label attacks are the right stress test because they're the hardest to detect—poisoned examples are visually indistinguishable from clean data. The paper reports that even a small number of verified poisoned examples provides a substantial advantage. A key empirical finding is that the distribution of verified clean examples across classes matters more than the raw count, which has practical implications for how you'd allocate your forensic verification budget. The integrity picture is solid but not exceptional. Seven attack methods on standard benchmarks is good breadth, and the clean-label focus is the right hard problem. But the abstract doesn't mention code availability, pre-registration, or independent replication. The verification assumption itself—that a forensic expert can reliably distinguish clean from poisoned examples—is load-bearing and somewhat circular: if expert verification were cheap and reliable at scale, you wouldn't need the defense. The practical bottleneck this paper addresses is real. In production ML pipelines ingesting public data, you can't verify everything. The insight that a small, carefully verified set (including known poisons) is more useful than a large assumed-clean set maps directly to how security teams actually operate—forensic analysis is expensive, so you want maximum signal from minimum inspections. The finding about class distribution over quantity is immediately actionable for anyone budgeting verification effort. What SAGE doesn't resolve is how you get those initial verified poisoned examples in the wild before an attack is known. The paper assumes a forensic expert can identify them, but in a zero-day poisoning scenario, you may not know what to look for. The method is strongest in the reactive case—once you've identified a few confirmed poisons from a known attack pattern, you can sweep the rest of the dataset efficiently.