Human-Imperceptible Retrieval Poisoning Attacks in LLM-Powered Applications
Fuente:
arXiv
Saved in:
| Main Authors: | Zhang, Quan, Zeng, Binqi, Zhou, Chijin, Go, Gwihwan, Shi, Heyuan, Jiang, Yu |
|---|---|
| Format: | Preprint |
| Published: |
2024
|
| Subjects: | |
| Online Access: | |
| Tags: |
Add Tag
No Tags, Be the first to tag this record!
|
Similar Items
Evaluating Privilege Usage of Agents with Real-World Tools
by: Zhang, Quan, et al.
Published: (2026)
by: Zhang, Quan, et al.
Published: (2026)
Inducing Vulnerable Code Generation in LLM Coding Assistants
by: Zeng, Binqi, et al.
Published: (2025)
by: Zeng, Binqi, et al.
Published: (2025)
Turning Generative Models Degenerate: The Power of Data Poisoning Attacks
by: Jiang, Shuli, et al.
Published: (2024)
by: Jiang, Shuli, et al.
Published: (2024)
Impart: An Imperceptible and Effective Label-Specific Backdoor Attack
by: Zhao, Jingke, et al.
Published: (2024)
by: Zhao, Jingke, et al.
Published: (2024)
LoopTrap: Termination Poisoning Attacks on LLM Agents
by: Xu, Huiyu, et al.
Published: (2026)
by: Xu, Huiyu, et al.
Published: (2026)
RevPRAG: Revealing Poisoning Attacks in Retrieval-Augmented Generation through LLM Activation Analysis
by: Tan, Xue, et al.
Published: (2024)
by: Tan, Xue, et al.
Published: (2024)
One Shot Dominance: Knowledge Poisoning Attack on Retrieval-Augmented Generation Systems
by: Chang, Zhiyuan, et al.
Published: (2025)
by: Chang, Zhiyuan, et al.
Published: (2025)
When the Manual Lies: A Realistic Benchmark to Evaluate MCP Poisoning Attacks for LLM Agents
by: Liu, Shi, et al.
Published: (2026)
by: Liu, Shi, et al.
Published: (2026)
Hidden in the Metadata: Stealth Poisoning Attacks on Multimodal Retrieval-Augmented Generation
by: Edemacu, Kennedy, et al.
Published: (2026)
by: Edemacu, Kennedy, et al.
Published: (2026)
Knowledge Poisoning Attacks on Medical Multi-Modal Retrieval-Augmented Generation
by: Yang, Peiru, et al.
Published: (2026)
by: Yang, Peiru, et al.
Published: (2026)
PIDP-Attack: Combining Prompt Injection with Database Poisoning Attacks on Retrieval-Augmented Generation Systems
by: Wang, Haozhen, et al.
Published: (2026)
by: Wang, Haozhen, et al.
Published: (2026)
BadSkill: Backdoor Attacks on Agent Skills via Model-in-Skill Poisoning
by: Tie, Guiyao, et al.
Published: (2026)
by: Tie, Guiyao, et al.
Published: (2026)
Joint-GCG: Unified Gradient-Based Poisoning Attacks on Retrieval-Augmented Generation Systems
by: Wang, Haowei, et al.
Published: (2025)
by: Wang, Haowei, et al.
Published: (2025)
Poison Once, Exploit Forever: Environment-Injected Memory Poisoning Attacks on Web Agents
by: Zou, Wei, et al.
Published: (2026)
by: Zou, Wei, et al.
Published: (2026)
Reasoning-Style Poisoning of LLM Agents via Stealthy Style Transfer: Process-Level Attacks and Runtime Monitoring in RSV Space
by: Zhou, Xingfu, et al.
Published: (2025)
by: Zhou, Xingfu, et al.
Published: (2025)
Supply-Chain Poisoning Attacks Against LLM Coding Agent Skill Ecosystems
by: Qu, Yubin, et al.
Published: (2026)
by: Qu, Yubin, et al.
Published: (2026)
Investigating Imperceptibility of Adversarial Attacks on Tabular Data: An Empirical Analysis
by: He, Zhipeng, et al.
Published: (2024)
by: He, Zhipeng, et al.
Published: (2024)
CompressionAttack: Exploiting Prompt Compression as a New Attack Surface in LLM-Powered Agents
by: Liu, Zesen, et al.
Published: (2025)
by: Liu, Zesen, et al.
Published: (2025)
CBPF: Filtering Poisoned Data Based on Composite Backdoor Attack
by: Xia, Hanfeng, et al.
Published: (2024)
by: Xia, Hanfeng, et al.
Published: (2024)
Defending Against Beta Poisoning Attacks in Machine Learning Models
by: Gulciftci, Nilufer, et al.
Published: (2025)
by: Gulciftci, Nilufer, et al.
Published: (2025)
When and Where do Data Poisons Attack Textual Inversion?
by: Styborski, Jeremy, et al.
Published: (2025)
by: Styborski, Jeremy, et al.
Published: (2025)
RouteGuard: Internal-Signal Detection of Skill Poisoning in LLM Agents
by: Xiao, Wenjie, et al.
Published: (2026)
by: Xiao, Wenjie, et al.
Published: (2026)
Unraveling the Connections between Privacy and Certified Robustness in Federated Learning Against Poisoning Attacks
by: Xie, Chulin, et al.
Published: (2022)
by: Xie, Chulin, et al.
Published: (2022)
CSC: Turning the Adversary's Poison against Itself
by: Shi, Yuchen, et al.
Published: (2026)
by: Shi, Yuchen, et al.
Published: (2026)
Precision Guided Approach to Mitigate Data Poisoning Attacks in Federated Learning
by: Kumar, K Naveen, et al.
Published: (2024)
by: Kumar, K Naveen, et al.
Published: (2024)
Nightshade: Prompt-Specific Poisoning Attacks on Text-to-Image Generative Models
by: Shan, Shawn, et al.
Published: (2023)
by: Shan, Shawn, et al.
Published: (2023)
Vulnerabilities in AI Code Generators: Exploring Targeted Data Poisoning Attacks
by: Cotroneo, Domenico, et al.
Published: (2023)
by: Cotroneo, Domenico, et al.
Published: (2023)
FIDELIS: Blockchain-Enabled Protection Against Poisoning Attacks in Federated Learning
by: Carney, Jane, et al.
Published: (2025)
by: Carney, Jane, et al.
Published: (2025)
FedCC: Robust Federated Learning against Model Poisoning Attacks
by: Jeong, Hyejun, et al.
Published: (2022)
by: Jeong, Hyejun, et al.
Published: (2022)
Dual Defense: Enhancing Privacy and Mitigating Poisoning Attacks in Federated Learning
by: Xu, Runhua, et al.
Published: (2025)
by: Xu, Runhua, et al.
Published: (2025)
LSPRAG: LSP-Guided RAG for Language-Agnostic Real-Time Unit Test Generation
by: Go, Gwihwan, et al.
Published: (2025)
by: Go, Gwihwan, et al.
Published: (2025)
MemoryGraft: Persistent Compromise of LLM Agents via Poisoned Experience Retrieval
by: Srivastava, Saksham Sahai, et al.
Published: (2025)
by: Srivastava, Saksham Sahai, et al.
Published: (2025)
Optimization-based Prompt Injection Attack to LLM-as-a-Judge
by: Shi, Jiawen, et al.
Published: (2024)
by: Shi, Jiawen, et al.
Published: (2024)
Adversarial Hubness Detector: Detecting Hubness Poisoning in Retrieval-Augmented Generation Systems
by: Habler, Idan, et al.
Published: (2026)
by: Habler, Idan, et al.
Published: (2026)
System Prompt Poisoning: Persistent Attacks on Large Language Models Beyond User Injection
by: Li, Zongze, et al.
Published: (2025)
by: Li, Zongze, et al.
Published: (2025)
A Set of Generalized Components to Achieve Effective Poison-only Clean-label Backdoor Attacks with Collaborative Sample Selection and Triggers
by: Wu, Zhixiao, et al.
Published: (2025)
by: Wu, Zhixiao, et al.
Published: (2025)
Robustness Analysis of Machine Learning Models for IoT Intrusion Detection Under Data Poisoning Attacks
by: Wulnye, Fortunatus Aabangbio, et al.
Published: (2026)
by: Wulnye, Fortunatus Aabangbio, et al.
Published: (2026)
Be Kind, Rewrite: Benign Projections via Rewriting Defend Against LLM Data Poisoning Attacks
by: Halloran, John T., et al.
Published: (2026)
by: Halloran, John T., et al.
Published: (2026)
From Poisoned to Aware: Fostering Backdoor Self-Awareness in LLMs
by: Shen, Guangyu, et al.
Published: (2025)
by: Shen, Guangyu, et al.
Published: (2025)
Hijacking Large Audio-Language Models via Context-Agnostic and Imperceptible Auditory Prompt Injection
by: Chen, Meng, et al.
Published: (2026)
by: Chen, Meng, et al.
Published: (2026)
Similar Items
-
Evaluating Privilege Usage of Agents with Real-World Tools
by: Zhang, Quan, et al.
Published: (2026) -
Inducing Vulnerable Code Generation in LLM Coding Assistants
by: Zeng, Binqi, et al.
Published: (2025) -
Turning Generative Models Degenerate: The Power of Data Poisoning Attacks
by: Jiang, Shuli, et al.
Published: (2024) -
Impart: An Imperceptible and Effective Label-Specific Backdoor Attack
by: Zhao, Jingke, et al.
Published: (2024) -
LoopTrap: Termination Poisoning Attacks on LLM Agents
by: Xu, Huiyu, et al.
Published: (2026)