Practical Poisoning Attacks against Retrieval-Augmented Generation

Fuente: arXiv
Salvato in:
Dettagli Bibliografici
Autori principali: Zhang, Baolei, Chen, Yuxi, Liu, Zhuqing, Nie, Lihai, Li, Tong, Liu, Zheli, Fang, Minghong
Natura: Preprint
Pubblicazione: 2025
Soggetti:
Accesso online:
Tags: Aggiungi Tag
Nessun Tag, puoi essere il primo ad aggiungerne!!
_version_ 1866908751922987008
author Zhang, Baolei
Chen, Yuxi
Liu, Zhuqing
Nie, Lihai
Li, Tong
Liu, Zheli
Fang, Minghong
author_facet Zhang, Baolei
Chen, Yuxi
Liu, Zhuqing
Nie, Lihai
Li, Tong
Liu, Zheli
Fang, Minghong
contents Large language models (LLMs) have demonstrated impressive natural language processing abilities but face challenges such as hallucination and outdated knowledge. Retrieval-Augmented Generation (RAG) has emerged as a state-of-the-art approach to mitigate these issues. While RAG enhances LLM outputs, it remains vulnerable to poisoning attacks. Recent studies show that injecting poisoned text into the knowledge database can compromise RAG systems, but most existing attacks assume that the attacker can insert a sufficient number of poisoned texts per query to outnumber correct-answer texts in retrieval, an assumption that is often unrealistic. To address this limitation, we propose CorruptRAG, a practical poisoning attack against RAG systems in which the attacker injects only a single poisoned text, enhancing both feasibility and stealth. Extensive experiments conducted on multiple large-scale datasets demonstrate that CorruptRAG achieves higher attack success rates than existing baselines.
format Preprint
id arxiv_https___arxiv_org_abs_2504_03957
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Practical Poisoning Attacks against Retrieval-Augmented Generation
Zhang, Baolei
Chen, Yuxi
Liu, Zhuqing
Nie, Lihai
Li, Tong
Liu, Zheli
Fang, Minghong
Cryptography and Security
Information Retrieval
Machine Learning
Large language models (LLMs) have demonstrated impressive natural language processing abilities but face challenges such as hallucination and outdated knowledge. Retrieval-Augmented Generation (RAG) has emerged as a state-of-the-art approach to mitigate these issues. While RAG enhances LLM outputs, it remains vulnerable to poisoning attacks. Recent studies show that injecting poisoned text into the knowledge database can compromise RAG systems, but most existing attacks assume that the attacker can insert a sufficient number of poisoned texts per query to outnumber correct-answer texts in retrieval, an assumption that is often unrealistic. To address this limitation, we propose CorruptRAG, a practical poisoning attack against RAG systems in which the attacker injects only a single poisoned text, enhancing both feasibility and stealth. Extensive experiments conducted on multiple large-scale datasets demonstrate that CorruptRAG achieves higher attack success rates than existing baselines.
title Practical Poisoning Attacks against Retrieval-Augmented Generation
topic Cryptography and Security
Information Retrieval
Machine Learning
url https://arxiv.org/abs/2504.03957