Lune

KDD2026顶会

SilentRetrieval: Hijacking Retrieval-Augmented Generation via Semantically-Preserving Adversarial Data Poisoning

Jiachen Qian

2026年份
1被引次数

摘要

Retrieval-Augmented Generation (RAG) mitigates LLM hallucinations but introduces a critical vulnerability: corpus integrity. We present SilentRetrieval, a two-stage data poisoning attack that hijacks RAG systems through adversarially crafted yet fluent documents. Stage 1 introduces Coordinated Beam Search (CBS), a multi-token joint optimization with a penalized fluency-similarity objective that preconditions a topically relevant host document to remain retrievable after payload insertion while constraining perplexity. Stage 2 employs Context-Adaptive Trigger Generation (CATG), a lightweight trigger-fusion step that uses a frozen LLM to generate triggers contextually integrated with document content. Under a one-poisoned-document-per-query evaluation with synthetic target answers, SilentRetrieval achieves 84.6%/81.3% HR@10 and 57.5%/54.8% ASR-LLM on Natural Questions (NQ, 361K-passage subset; not the standard 21M DPR corpus) and MS MARCO (8.8M passages), while maintaining near-benign perplexity (32.4 vs. 28.4). Cross-model evaluation across four target LLMs shows nontrivial effectiveness under a fixed CATG generator (48.6-57.5% ASR-LLM). Surrogate-transfer evaluation against unseen retrievers, including ColBERT and rebuilt indexes using commercial embedding models, yields 64.7% average HR@10 under the same injected-corpus protocol. In a sampled large-corpus evaluation built from a Wikipedia-scale 21M-passage construction, SilentRetrieval retains 74.2% HR@10 at a 0.016% poisoning ratio, characterizing large-corpus behavior under the sampled protocol. Combined retrieval-side and generation-side defenses reduce ASR-LLM to 25.6% at a 6x latency trade-off in our evaluated setting, and to 21.3% under the strongest evaluated configuration; adaptive attacks recover 6.2% HR@10 in the matched MiniLM-L6-v2 reranker setting. Human evaluation (n=600 documents, Krippendorff's α=0.74) shows substantially lower flag rates than disfluent baselines, while remaining numerically more suspicious than benign content at the current sample size (p≈0.064).

问问这篇 Paper

智能体会读完全文。

Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。

可以从这些问题问起

智能体调用

Luneget_paper_fulltext

在 Lune 里问

免费开始,无需绑卡

它引用的顶会 Paper12

相关 Paper

黄昏的海面,两侧是细线勾勒的悬崖