Through the Stealth Lens: Attention-Aware Defenses Against Poisoning in RAG
Fuente:
arXiv
Saved in:
| Main Authors: | Choudhary, Sarthak, Palumbo, Nils, Hooda, Ashish, Dvijotham, Krishnamurthy Dj, Jha, Somesh |
|---|---|
| Format: | Preprint |
| Published: |
2025
|
| Subjects: | |
| Online Access: | |
| Tags: |
Add Tag
No Tags, Be the first to tag this record!
|
Similar Items
Undetectable Backdoors in Model Parameters: Hiding Sparse Secrets in High Dimensions
by: Choudhary, Sarthak, et al.
Published: (2026)
by: Choudhary, Sarthak, et al.
Published: (2026)
How Not to Detect Prompt Injections with an LLM
by: Choudhary, Sarthak, et al.
Published: (2025)
by: Choudhary, Sarthak, et al.
Published: (2025)
Dependency-Aware Privacy for Multi-turn Agents
by: Anshumaan, Divyam, et al.
Published: (2026)
by: Anshumaan, Divyam, et al.
Published: (2026)
Formal Policy Enforcement for Real-World Agentic Systems
by: Palumbo, Nils, et al.
Published: (2026)
by: Palumbo, Nils, et al.
Published: (2026)
Agent Security is a Systems Problem
by: Christodorescu, Mihai, et al.
Published: (2026)
by: Christodorescu, Mihai, et al.
Published: (2026)
Functional Homotopy: Smoothing Discrete Optimization via Continuous Parameters for LLM Jailbreak Attacks
by: Wang, Zi, et al.
Published: (2024)
by: Wang, Zi, et al.
Published: (2024)
Hidden in the Metadata: Stealth Poisoning Attacks on Multimodal Retrieval-Augmented Generation
by: Edemacu, Kennedy, et al.
Published: (2026)
by: Edemacu, Kennedy, et al.
Published: (2026)
Semantic Chameleon: Corpus-Dependent Poisoning Attacks and Defenses in RAG Systems
by: Thornton, Scott
Published: (2026)
by: Thornton, Scott
Published: (2026)
VeriGuard: Enhancing LLM Agent Safety via Verified Code Generation
by: Miculicich, Lesly, et al.
Published: (2025)
by: Miculicich, Lesly, et al.
Published: (2025)
SuperLocalMemory: Privacy-Preserving Multi-Agent Memory with Bayesian Trust Defense Against Memory Poisoning
by: Bhardwaj, Varun Pratap
Published: (2026)
by: Bhardwaj, Varun Pratap
Published: (2026)
Systems Security Foundations for Agentic Computing
by: Christodorescu, Mihai, et al.
Published: (2025)
by: Christodorescu, Mihai, et al.
Published: (2025)
Defense Against Model Stealing Based on Account-Aware Distribution Discrepancy
by: Mei, Jian-Ping, et al.
Published: (2025)
by: Mei, Jian-Ping, et al.
Published: (2025)
Adversarial Machine Learning: Attacks, Defenses, and Open Challenges
by: Jha, Pranav K
Published: (2025)
by: Jha, Pranav K
Published: (2025)
PolicyLR: A Logic Representation For Privacy Policies
by: Hooda, Ashish, et al.
Published: (2024)
by: Hooda, Ashish, et al.
Published: (2024)
ReliabilityRAG: Effective and Provably Robust Defense for RAG-based Web-Search
by: Shen, Zeyu, et al.
Published: (2025)
by: Shen, Zeyu, et al.
Published: (2025)
What Really is a Member? Discrediting Membership Inference via Poisoning
by: Mangaokar, Neal, et al.
Published: (2025)
by: Mangaokar, Neal, et al.
Published: (2025)
Dual Defense: Enhancing Privacy and Mitigating Poisoning Attacks in Federated Learning
by: Xu, Runhua, et al.
Published: (2025)
by: Xu, Runhua, et al.
Published: (2025)
A New Era in LLM Security: Exploring Security Concerns in Real-World LLM-based Systems
by: Wu, Fangzhou, et al.
Published: (2024)
by: Wu, Fangzhou, et al.
Published: (2024)
Behavior-Aware and Generalizable Defense Against Black-Box Adversarial Attacks for ML-Based IDS
by: Ennaji, Sabrine, et al.
Published: (2025)
by: Ennaji, Sabrine, et al.
Published: (2025)
The Defense Trilemma: Why Prompt Injection Defense Wrappers Fail?
by: Bhatt, Manish, et al.
Published: (2026)
by: Bhatt, Manish, et al.
Published: (2026)
Defending Against Beta Poisoning Attacks in Machine Learning Models
by: Gulciftci, Nilufer, et al.
Published: (2025)
by: Gulciftci, Nilufer, et al.
Published: (2025)
Attacking Byzantine Robust Aggregation in High Dimensions
by: Choudhary, Sarthak, et al.
Published: (2023)
by: Choudhary, Sarthak, et al.
Published: (2023)
Malice in Agentland: Down the Rabbit Hole of Backdoors in the AI Supply Chain
by: Boisvert, Léo, et al.
Published: (2025)
by: Boisvert, Léo, et al.
Published: (2025)
From Poisoned to Aware: Fostering Backdoor Self-Awareness in LLMs
by: Shen, Guangyu, et al.
Published: (2025)
by: Shen, Guangyu, et al.
Published: (2025)
Cordon-MAS: Defending RAG against Knowledge Poisoning via Information-Flow Control
by: Yu, Zhe, et al.
Published: (2026)
by: Yu, Zhe, et al.
Published: (2026)
FIDELIS: Blockchain-Enabled Protection Against Poisoning Attacks in Federated Learning
by: Carney, Jane, et al.
Published: (2025)
by: Carney, Jane, et al.
Published: (2025)
Phantom Transfer: Data-level Defences are Insufficient Against Data Poisoning
by: Draganov, Andrew, et al.
Published: (2026)
by: Draganov, Andrew, et al.
Published: (2026)
Class-Conditional Neural Polarizer: A Lightweight and Effective Backdoor Defense by Purifying Poisoned Features
by: Zhu, Mingli, et al.
Published: (2025)
by: Zhu, Mingli, et al.
Published: (2025)
P2P: A Poison-to-Poison Remedy for Reliable Backdoor Defense in LLMs
by: Zhao, Shuai, et al.
Published: (2025)
by: Zhao, Shuai, et al.
Published: (2025)
Defenses Against Prompt Attacks Learn Surface Heuristics
by: Li, Shawn, et al.
Published: (2026)
by: Li, Shawn, et al.
Published: (2026)
Stealthy Poisoning Attacks Bypass Defenses in Regression Settings
by: Carnerero-Cano, Javier, et al.
Published: (2026)
by: Carnerero-Cano, Javier, et al.
Published: (2026)
Confused ChatGPT: Cross-App Context Poisoning via First-Party APIs
by: Wang, Chao, et al.
Published: (2026)
by: Wang, Chao, et al.
Published: (2026)
Enhancing Model Defense Against Jailbreaks with Proactive Safety Reasoning
by: Yang, Xianglin, et al.
Published: (2025)
by: Yang, Xianglin, et al.
Published: (2025)
Unraveling the Connections between Privacy and Certified Robustness in Federated Learning Against Poisoning Attacks
by: Xie, Chulin, et al.
Published: (2022)
by: Xie, Chulin, et al.
Published: (2022)
SoK: Benchmarking Poisoning Attacks and Defenses in Federated Learning
by: Zhang, Heyi, et al.
Published: (2025)
by: Zhang, Heyi, et al.
Published: (2025)
Data to Defense: The Role of Curation in Customizing LLMs Against Jailbreaking Attacks
by: Liu, Xiaoqun, et al.
Published: (2024)
by: Liu, Xiaoqun, et al.
Published: (2024)
WARD: Adversarially Robust Defense of Web Agents Against Prompt Injections
by: Cao, Tri, et al.
Published: (2026)
by: Cao, Tri, et al.
Published: (2026)
WeiDetect: Weibull Distribution-Based Defense against Poisoning Attacks in Federated Learning for Network Intrusion Detection Systems
by: M., Sameera K., et al.
Published: (2025)
by: M., Sameera K., et al.
Published: (2025)
MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents
by: Zhu, Kaijie, et al.
Published: (2025)
by: Zhu, Kaijie, et al.
Published: (2025)
DELMAN: Dynamic Defense Against Large Language Model Jailbreaking with Model Editing
by: Wang, Yi, et al.
Published: (2025)
by: Wang, Yi, et al.
Published: (2025)
Similar Items
-
Undetectable Backdoors in Model Parameters: Hiding Sparse Secrets in High Dimensions
by: Choudhary, Sarthak, et al.
Published: (2026) -
How Not to Detect Prompt Injections with an LLM
by: Choudhary, Sarthak, et al.
Published: (2025) -
Dependency-Aware Privacy for Multi-turn Agents
by: Anshumaan, Divyam, et al.
Published: (2026) -
Formal Policy Enforcement for Real-World Agentic Systems
by: Palumbo, Nils, et al.
Published: (2026) -
Agent Security is a Systems Problem
by: Christodorescu, Mihai, et al.
Published: (2026)