Hidden-in-Plain-Text: A Benchmark for Social-Web Indirect Prompt Injection in RAG

Fuente: arXiv
Guardado en:
Detalles Bibliográficos
Autores principales: Guo, Haoze, Wei, Ziqi
Formato: Preprint
Publicado: 2026
Materias:
Acceso en línea:
Etiquetas: Agregar Etiqueta
Sin Etiquetas, Sea el primero en etiquetar este registro!
_version_ 1866909996377178112
author Guo, Haoze
Wei, Ziqi
author_facet Guo, Haoze
Wei, Ziqi
contents Retrieval-augmented generation (RAG) systems put more and more emphasis on grounding their responses in user-generated content found on the Web, amplifying both their usefulness and their attack surface. Most notably, indirect prompt injection and retrieval poisoning attack the web-native carriers that survive ingestion pipelines and are very concerning. We provide OpenRAG-Soc, a compact, reproducible benchmark-and-harness for web-facing RAG evaluation under these threats, in a discrete data package. The suite combines a social corpus with interchangeable sparse and dense retrievers and deployable mitigations - HTML/Markdown sanitization, Unicode normalization, and attribution-gated answered. It standardizes end-to-end evaluation from ingestion to generation and reports attacks time of one of the responses at answer time, rank shifts in both sparse and dense retrievers, utility and latency, allowing for apples-to-apples comparisons across carriers and defenses. OpenRAG-Soc targets practitioners who need fast, and realistic tests to track risk and harden deployments.
format Preprint
id arxiv_https___arxiv_org_abs_2601_10923
institution arXiv
publishDate 2026
record_format arxiv
spellingShingle Hidden-in-Plain-Text: A Benchmark for Social-Web Indirect Prompt Injection in RAG
Guo, Haoze
Wei, Ziqi
Cryptography and Security
Human-Computer Interaction
Retrieval-augmented generation (RAG) systems put more and more emphasis on grounding their responses in user-generated content found on the Web, amplifying both their usefulness and their attack surface. Most notably, indirect prompt injection and retrieval poisoning attack the web-native carriers that survive ingestion pipelines and are very concerning. We provide OpenRAG-Soc, a compact, reproducible benchmark-and-harness for web-facing RAG evaluation under these threats, in a discrete data package. The suite combines a social corpus with interchangeable sparse and dense retrievers and deployable mitigations - HTML/Markdown sanitization, Unicode normalization, and attribution-gated answered. It standardizes end-to-end evaluation from ingestion to generation and reports attacks time of one of the responses at answer time, rank shifts in both sparse and dense retrievers, utility and latency, allowing for apples-to-apples comparisons across carriers and defenses. OpenRAG-Soc targets practitioners who need fast, and realistic tests to track risk and harden deployments.
title Hidden-in-Plain-Text: A Benchmark for Social-Web Indirect Prompt Injection in RAG
topic Cryptography and Security
Human-Computer Interaction
url https://arxiv.org/abs/2601.10923