On the Vulnerability of Applying Retrieval-Augmented Generation within Knowledge-Intensive Application Domains
Xun Xian, Ganghua Wang, Xuan Bi, Rui Zhang, Jayanth Srinivasa, Ashish Kundu, Charles Fleming, Mingyi Hong, Jie Ding
摘要
Retrieval-Augmented Generation (RAG) has been empirically shown to enhance the performance of large language models (LLMs) in knowledge-intensive domains such as healthcare, finance, and legal contexts. Given a query, RAG retrieves relevant documents from a corpus and integrates them into the LLMs' generation process. In this study, we investigate the adversarial robustness of RAG, focusing specifically on examining the retrieval system. First, across 225 different setup combinations of corpus, retriever, query, and targeted information, we show that retrieval systems are vulnerable to universal poisoning attacks in medical Q&A. In such attacks, adversaries generate poisoned documents containing a broad spectrum of targeted information, such as personally identifiable information. When these poisoned documents are inserted into a corpus, they can be accurately retrieved by any users, as long as attacker-specified queries are used. To understand this vulnerability, we discovered that the deviation from the query's embedding to that of the poisoned document tends to follow a pattern in which the high similarity between the poisoned document and the query is retained, thereby enabling precise retrieval. Based on these findings, we develop a new detection-based defense. Through extensive experiments spanning various Q&A domains, we observed that our proposed method consistently achieves excellent detection rates in nearly all cases. particularly concerning in domains require extensive knowledge, such as healthcare [6, 7] , finance [8] and legal question-answering [9] . These challenges have sparked interest in more principled methods for decoding and alignment [10], as well as techniques that inject external knowledge to bridge domain gaps, such as Retrieval-Augmented Generation (RAG) [11] [12] [13] [14] . The RAG approach typically involves two steps: retrieval and augmentation. Upon receiving an input query, RAG retrieves the top K relevant data from an external data corpus. It then integrates this retrieved information with its internal knowledge to make final predictions. Empirical evidence suggests that LLMs employing the RAG scheme significantly outperform their non-retrieval-based counterparts in knowledge-intensive domains like finance and medicine [13, 14] . For instance, the authors of [14] developed a state-of-the-art benchmark for the use of RAG in the medical domain. The authors observed an increase in prediction accuracy of up to 18% with RAG compared to non-retrieval and chain-of-thoughts versions across large-scale healthcare tasks, utilizing 41 different combinations of medical data corpora, retrievers, and LLMs. The use of retrieved knowledge in RAG has also raised security and privacy concerns, especially when the external data corpus is openly accessible, e.g., Wikipedia [15, 16] and PubMed, or when controlled by potential malicious agents, as demonstrated in the case of multi-vision-LLM agents [17] . For example, recent work has successfully launched data poisoning attacks against the retrieval systems [15, 16, 18, 19] . In these cases, malicious attackers can poison a publicly accessible data corpus by injecting attacker-specified data into it, aiming to trick the retrieval system into retrieving those target data as the top K relevant documents. Consequently, when LLMs make predictions based on the retrieved data, they can be easily targeted by adversaries through backdoor attacks [15] . With the empirical successes of these attacks, it is imperative to develop defenses against them. However, existing methods, such as examining the ℓ 2 -norm of the documents' embeddings, have been shown to be ineffective [16] for detecting poisoned documents. Given the widespread adoption of RAG in safety-critical domains such as healthcare, such safety risks become even more pronounced. Main Contributions In this study, we investigate the safety risks associated with RAG, specifically focusing on retrieval systems. The contributions are summarized as follows. Revealing the safety risks for retrieval systems: case studies for medical Q&A and legal Q&A. We demonstrate that dense retrieval systems are vulnerable to what we term 'universal poisoning attacks' in medical Q&A across 225 use-case combinations of corpus, retriever, query, and targeted information. Similar observations are made for legal Q&A. As shown in Figure 1 below, in these attacks, adversaries can append nearly every sort of information, such as personally identifiable information (PII) and adversarial treatment recommendations, to a set of attacker-specified queries. Once these poisoned documents are injected into a large-scale corpus, such as Wikipedia and PubMed, they can be accurately retrieved, often with high rankings, e.g., top 1, using attacker-specified queries. Depending on attackers' goals, these documents will lead to safety risks such as (1) leakage of PII, (2) adversarial recommendations for treatments, and (3) jailbreaking the
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper3
- GraphRAG Under FireJiacheng Liang, Yuhui Wang, Changjiang Li, Tanqiu Jiang 等S&P 2026 · 被引用 31 次
- InceptionRAG: Stealthy Poisoning Attack Against Retrieval-Augmented GenerationJiachang Zhang, Min Chen, Xiao Ren, Zhenyong Zhang 等CCS 2026
- Knowledge Poisoning Attacks on Medical Multi-Modal Retrieval-Augmented GenerationPeiru Yang, Haoran Zheng, Tong Ju, Shiting Wang 等ACL 2026
它引用的顶会 Paper14
- A Simple Framework for Contrastive Learning of Visual RepresentationsTing Chen, Simon Kornblith, Mohammad Norouzi, Geoffrey E. HintonICML 2020 · 被引用 24,064 次
- Retrieval-Augmented Generation for Knowledge-Intensive NLP TasksPatrick Lewis, Ethan Perez, Aleksandra Piktus, Fabio Petroni 等NeurIPS 2020 · 被引用 19,162 次
- Improving Language Models by Retrieving from Trillions of TokensSebastian Borgeaud, Arthur Mensch, Jordan Hoffmann, Trevor Cai 等ICML 2022 · 被引用 1,629 次
- Generalization through Memorization: Nearest Neighbor Language ModelsUrvashi Khandelwal, Omer Levy, Dan Jurafsky, Luke Zettlemoyer 等ICLR 2020 · 被引用 1,038 次
- Agent Smith: A Single Image Can Jailbreak One Million Multimodal LLM Agents Exponentially FastXiangming Gu, Xiaosen Zheng, Tianyu Pang, Chao Du 等ICML 2024 · 被引用 128 次
相关 Paper
- WARP: A Word-Level Backdoor Attack Targeting RAG Systems via Retrieval Corpus PoisoningHui Liu, Yibo Zhou, Liguo Dong, Weidong Li 等KDD 2026
- IRAG: Robust Multimodal Retrieval-Augmented Generation via Hazard SeparationRuikun Luo, Zixiao Feng, Lin Gu, Xiaoyu XiaWWW 2026
- Joint-GCG: Unified Gradient-Based Poisoning Attacks on Retrieval-Augmented Generation SystemsHaowei Wang, Rupeng Zhang, Junjie Wang, Mingyang Li 等AAAI 2026 · 被引用 3 次
- ShieldRAG: Safeguarding Retrieval-Augmented Generation from Untrusted Knowledge BasesPeiru Yang, Haoran Zheng, Yi Luo, Xinyi Liu 等AAAI 2026
- PR-Attack: Coordinated Prompt-RAG Attacks on Retrieval-Augmented Generation in Large Language Models via Bilevel OptimizationYang Jiao, Xiaodong Wang, Kai YangSIGIR 2025 · 被引用 6 次
