Saved in:
| Main Authors: | Ye, Hengkai, Zhang, Zhechang, Jia, Jinyuan, Hu, Hong |
|---|---|
| Format: | Preprint |
| Published: |
2026
|
| Subjects: | |
| Online Access: | https://arxiv.org/abs/2604.07536 |
| Tags: |
Add Tag
No Tags, Be the first to tag this record!
|
Similar Items
PoisonedRAG: Knowledge Corruption Attacks to Retrieval-Augmented Generation of Large Language Models
by: Zou, Wei, et al.
Published: (2024)
by: Zou, Wei, et al.
Published: (2024)
SecInfer: Preventing Prompt Injection via Inference-time Scaling
by: Liu, Yupei, et al.
Published: (2025)
by: Liu, Yupei, et al.
Published: (2025)
Sugar-Coated Poison: Benign Generation Unlocks LLM Jailbreaking
by: Wu, Yu-Hang, et al.
Published: (2025)
by: Wu, Yu-Hang, et al.
Published: (2025)
Evaluating LLM-based Personal Information Extraction and Countermeasures
by: Liu, Yupei, et al.
Published: (2024)
by: Liu, Yupei, et al.
Published: (2024)
MalTool: Malicious Tool Attacks on LLM Agents
by: Hu, Yuepeng, et al.
Published: (2026)
by: Hu, Yuepeng, et al.
Published: (2026)
Poisoning Prevention in Federated Learning and Differential Privacy via Stateful Proofs of Execution
by: Rattanavipanon, Norrathep, et al.
Published: (2024)
by: Rattanavipanon, Norrathep, et al.
Published: (2024)
CorruptEncoder: Data Poisoning based Backdoor Attacks to Contrastive Learning
by: Zhang, Jinghuai, et al.
Published: (2022)
by: Zhang, Jinghuai, et al.
Published: (2022)
EnsembleSHAP: Faithful and Certifiably Robust Attribution for Random Subspace Method
by: Wang, Yanting, et al.
Published: (2026)
by: Wang, Yanting, et al.
Published: (2026)
Human-Imperceptible Retrieval Poisoning Attacks in LLM-Powered Applications
by: Zhang, Quan, et al.
Published: (2024)
by: Zhang, Quan, et al.
Published: (2024)
ACE: A Model Poisoning Attack on Contribution Evaluation Methods in Federated Learning
by: Xu, Zhangchen, et al.
Published: (2024)
by: Xu, Zhangchen, et al.
Published: (2024)
Deep-Research Agents Can Be Poisoned via User-Generated Content
by: Zhang, Tingwei, et al.
Published: (2026)
by: Zhang, Tingwei, et al.
Published: (2026)
TracLLM: A Generic Framework for Attributing Long Context LLMs
by: Wang, Yanting, et al.
Published: (2025)
by: Wang, Yanting, et al.
Published: (2025)
KeTS: Kernel-based Trust Segmentation against Model Poisoning Attacks
by: Gangwal, Ankit, et al.
Published: (2025)
by: Gangwal, Ankit, et al.
Published: (2025)
Trust No Tool: Evaluating and Defending LLM Agents under Untrusted Tool Feedback
by: Yan, Lecheng, et al.
Published: (2026)
by: Yan, Lecheng, et al.
Published: (2026)
Distributed Backdoor Attacks on Federated Graph Learning and Certified Defenses
by: Yang, Yuxin, et al.
Published: (2024)
by: Yang, Yuxin, et al.
Published: (2024)
PIShield: Detecting Prompt Injection Attacks via Intrinsic LLM Features
by: Zou, Wei, et al.
Published: (2025)
by: Zou, Wei, et al.
Published: (2025)
Federated TrustChain: Blockchain-Enhanced LLM Training and Unlearning
by: Zuo, Xuhan, et al.
Published: (2024)
by: Zuo, Xuhan, et al.
Published: (2024)
FCert: Certifiably Robust Few-Shot Classification in the Era of Foundation Models
by: Wang, Yanting, et al.
Published: (2024)
by: Wang, Yanting, et al.
Published: (2024)
Data Poisoning Attacks to Local Differential Privacy Protocols for Graphs
by: He, Xi, et al.
Published: (2024)
by: He, Xi, et al.
Published: (2024)
TASO: Jailbreak LLMs via Alternative Template and Suffix Optimization
by: Wang, Yanting, et al.
Published: (2025)
by: Wang, Yanting, et al.
Published: (2025)
Defending Against Neural Network Model Inversion Attacks via Data Poisoning
by: Zhou, Shuai, et al.
Published: (2024)
by: Zhou, Shuai, et al.
Published: (2024)
PoisonCatcher: Revealing and Identifying LDP Poisoning Attacks in IIoT
by: Shuai, Lisha, et al.
Published: (2024)
by: Shuai, Lisha, et al.
Published: (2024)
Detecting and Preventing Data Poisoning Attacks on AI Models
by: Kure, Halima I., et al.
Published: (2025)
by: Kure, Halima I., et al.
Published: (2025)
PISanitizer: Preventing Prompt Injection to Long-Context LLMs via Prompt Sanitization
by: Geng, Runpeng, et al.
Published: (2025)
by: Geng, Runpeng, et al.
Published: (2025)
Pandora: Jailbreak GPTs by Retrieval Augmented Generation Poisoning
by: Deng, Gelei, et al.
Published: (2024)
by: Deng, Gelei, et al.
Published: (2024)
LDPRecover: Recovering Frequencies from Poisoning Attacks against Local Differential Privacy
by: Sun, Xinyue, et al.
Published: (2024)
by: Sun, Xinyue, et al.
Published: (2024)
Low Rank Comes with Low Security: Gradient Assembly Poisoning Attacks against Distributed LoRA-based LLM Systems
by: Dong, Yueyan, et al.
Published: (2026)
by: Dong, Yueyan, et al.
Published: (2026)
AgentWatcher: A Rule-based Prompt Injection Monitor
by: Wang, Yanting, et al.
Published: (2026)
by: Wang, Yanting, et al.
Published: (2026)
FlashRT: Towards Computationally and Memory Efficient Red-Teaming for Prompt Injection and Knowledge Corruption
by: Wang, Yanting, et al.
Published: (2026)
by: Wang, Yanting, et al.
Published: (2026)
VENOMREC: Cross-Modal Interactive Poisoning for Targeted Promotion in Multimodal LLM Recommender Systems
by: Guan, Guowei, et al.
Published: (2026)
by: Guan, Guowei, et al.
Published: (2026)
Securing Voice Authentication Applications Against Targeted Data Poisoning
by: Mohammadi, Alireza, et al.
Published: (2024)
by: Mohammadi, Alireza, et al.
Published: (2024)
Silent Guardians: Independent and Secure Decision Tree Evaluation Without Chatter
by: Li, Jinyuan, et al.
Published: (2026)
by: Li, Jinyuan, et al.
Published: (2026)
RouteGuard: Internal-Signal Detection of Skill Poisoning in LLM Agents
by: Xiao, Wenjie, et al.
Published: (2026)
by: Xiao, Wenjie, et al.
Published: (2026)
Confundo: Learning to Generate Robust Poison for Practical RAG Systems
by: Hu, Haoyang, et al.
Published: (2026)
by: Hu, Haoyang, et al.
Published: (2026)
RAGRank: Using PageRank to Counter Poisoning in CTI LLM Pipelines
by: Jia, Austin, et al.
Published: (2025)
by: Jia, Austin, et al.
Published: (2025)
AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases
by: Chen, Zhaorun, et al.
Published: (2024)
by: Chen, Zhaorun, et al.
Published: (2024)
Train in Vain: Functionality-Preserving Poisoning to Prevent Unauthorized Use of Code Datasets
by: Xiao, Yuan, et al.
Published: (2026)
by: Xiao, Yuan, et al.
Published: (2026)
MCP-ITP: An Automated Framework for Implicit Tool Poisoning in MCP
by: Li, Ruiqi, et al.
Published: (2026)
by: Li, Ruiqi, et al.
Published: (2026)
MindGuard: Intrinsic Decision Inspection for Securing LLM Agents Against Metadata Poisoning
by: Wang, Zhiqiang, et al.
Published: (2025)
by: Wang, Zhiqiang, et al.
Published: (2025)
Generate "Normal", Edit Poisoned: Branding Injection via Hint Embedding in Image Editing
by: Sun, Desen, et al.
Published: (2026)
by: Sun, Desen, et al.
Published: (2026)
Similar Items
-
PoisonedRAG: Knowledge Corruption Attacks to Retrieval-Augmented Generation of Large Language Models
by: Zou, Wei, et al.
Published: (2024) -
SecInfer: Preventing Prompt Injection via Inference-time Scaling
by: Liu, Yupei, et al.
Published: (2025) -
Sugar-Coated Poison: Benign Generation Unlocks LLM Jailbreaking
by: Wu, Yu-Hang, et al.
Published: (2025) -
Evaluating LLM-based Personal Information Extraction and Countermeasures
by: Liu, Yupei, et al.
Published: (2024) -
MalTool: Malicious Tool Attacks on LLM Agents
by: Hu, Yuepeng, et al.
Published: (2026)