Silent Leaks: Implicit Knowledge Extraction Attack on RAG Systems
Yuhao Wang, Wenjie Qu, Shengfang Zhai, Yanze Jiang, Zichen Liu, Yue Liu, Yinpeng Dong, Jiaheng Zhang
摘要
Retrieval-Augmented Generation (RAG) systems enhance large language models (LLMs) by incorporating external knowledge bases, but this may expose them to extraction attacks, leading to potential copyright and privacy risks. However, existing extraction methods typically rely on malicious inputs such as prompt injection or jailbreaking, making them easily detectable via input- or output-level detection. In this paper, we introduce Implicit Knowledge Extraction Attack (IKEA), which conducts Knowledge Extraction on RAG systems through benign queries. Specifically, IKEA first leverages anchor concepts—keywords related to internal knowledge—to generate queries with a natural appearance, and then designs two mechanisms that lead anchor concepts to thoroughly "explore" the RAG's knowledge: (1) Experience Reflection Sampling, which samples anchor concepts based on past query-response histories, ensuring their relevance to the topic; (2) Trust Region Directed Mutation, which iteratively mutates anchor concepts under similarity constraints to further exploit the embedding space. Extensive experiments demonstrate IKEA's effectiveness under various defenses, surpassing baselines by over 80% in extraction efficiency and 90% in attack success rate. Moreover, the substitute RAG system built from IKEA's extractions shows close performance to the original RAG and outperforms those based on baselines across multiple evaluation tasks, underscoring the stealthy copyright infringement risk in RAG systems.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper4
- Connect the Dots: Knowledge Graph–Guided Crawler Attack on Retrieval-Augmented Generation SystemsMengyu Yao, Ziqi Zhang, Ning Luo, Shaofei Li 等USENIX Security 2026 · 被引用 3 次
- AliMark: Enhancing Robustness of Sentence-Level Watermarking Against Text ParaphrasingYuexin Li, Wenjie Qu, Linyu Wu, Yulin Chen 等ICML 2026
- Towards Whole-corpus Reconstruction of Heterogeneous RAG Knowledge BasesPeiru Yang, Yi Luo, Zhenfeng Gao, Tong Ju 等ICML 2026
- MemIncept: Steering LLM Agents via Cooperative Stealthy Memory InjectionsNan Yan, Qian Lou, Jiarong XingICML 2026
它引用的顶会 Paper9
- Retrieval-Augmented Generation for Knowledge-Intensive NLP TasksPatrick Lewis, Ethan Perez, Aleksandra Piktus, Fabio Petroni 等NeurIPS 2020 · 被引用 19,162 次
- MPNet: Masked and Permuted Pre-training for Language UnderstandingKaitao Song, Xu Tan, Tao Qin, Jianfeng Lu 等NeurIPS 2020 · 被引用 1,957 次
- Bridging the Preference Gap between Retrievers and LLMsZixuan Ke, Weize Kong, Cheng Li, Mingyang Zhang 等ACL 2024 · 被引用 8 次
- Mitigating the Privacy Issues in Retrieval-Augmented Generation (RAG) via Pure Synthetic DataShenglai Zeng, Jiankun Zhang, Pengfei He, Jie Ren 等EMNLP 2025 · 被引用 7 次
- MMed-RAG: Versatile Multimodal RAG System for Medical Vision Language ModelsPeng Xia, Kangyu Zhu, Haoran Li, Tianze Wang 等ICLR 2025 · 被引用 5 次
相关 Paper
- Riddle Me This! Stealthy Membership Inference for Retrieval-Augmented GenerationAli Naseh, Yuefeng Peng, Anshuman Suri, Harsh Chaudhari 等CCS 2025
- AIP: Subverting Retrieval-Augmented Generation via Adversarial Instructional PromptSaket S. Chaturvedi, Gaurav Bagwe, Lan Zhang, Xiaoyong YuanEMNLP 2025
- Fine-Grained Privacy Extraction from Retrieval-Augmented Generation Systems by Exploiting Knowledge AsymmetryYufei Chen, Yao Wang, Haibin Zhang, Tao GuICLR 2026 · 被引用 2 次
- RAGFort: Dual-Path Defense Against Proprietary Knowledge Base Extraction in Retrieval-Augmented GenerationQinfeng Li, Miao Pan, Ke Xiong, Ge Su 等AAAI 2026
- On the Vulnerability of Applying Retrieval-Augmented Generation within Knowledge-Intensive Application DomainsXun Xian, Ganghua Wang, Xuan Bi, Rui Zhang 等ICML 2025
