When RAG Chatbots Expose Their Backend: An Anonymized Case Study of Privacy and Security Risks in Patient-Facing Medical AI
Fuente:
arXiv
Gespeichert in:
| Hauptverfasser: | Madrid-García, Alfredo, Rujas, Miguel |
|---|---|
| Format: | Preprint |
| Veröffentlicht: |
2026
|
| Schlagworte: | |
| Online-Zugang: | |
| Tags: |
Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
|
Ähnliche Einträge
BaxBench: Can LLMs Generate Correct and Secure Backends?
von: Vero, Mark, et al.
Veröffentlicht: (2025)
von: Vero, Mark, et al.
Veröffentlicht: (2025)
When AI Meets the Web: Prompt Injection Risks in Third-Party AI Chatbot Plugins
von: Kaya, Yigitcan, et al.
Veröffentlicht: (2025)
von: Kaya, Yigitcan, et al.
Veröffentlicht: (2025)
Design and Implementation of a Secure RAG-Enhanced AI Chatbot for Smart Tourism Customer Service: Defending Against Prompt Injection Attacks -- A Case Study of Hsinchu, Taiwan
von: Shih, Yu-Kai, et al.
Veröffentlicht: (2025)
von: Shih, Yu-Kai, et al.
Veröffentlicht: (2025)
GradingAttack: Exposing Security Vulnerabilities in LLM Based Educational Grading Agents
von: Li, Xueyi, et al.
Veröffentlicht: (2026)
von: Li, Xueyi, et al.
Veröffentlicht: (2026)
Guarding Your Conversations: Privacy Gatekeepers for Secure Interactions with Cloud-Based AI Models
von: Uzor, GodsGift, et al.
Veröffentlicht: (2025)
von: Uzor, GodsGift, et al.
Veröffentlicht: (2025)
Privacy-Aware RAG: Secure and Isolated Knowledge Retrieval
von: Zhou, Pengcheng, et al.
Veröffentlicht: (2025)
von: Zhou, Pengcheng, et al.
Veröffentlicht: (2025)
The Good and The Bad: Exploring Privacy Issues in Retrieval-Augmented Generation (RAG)
von: Zeng, Shenglai, et al.
Veröffentlicht: (2024)
von: Zeng, Shenglai, et al.
Veröffentlicht: (2024)
RAG Security and Privacy: Formalizing the Threat Model and Attack Surface
von: Arzanipour, Atousa, et al.
Veröffentlicht: (2025)
von: Arzanipour, Atousa, et al.
Veröffentlicht: (2025)
PyRIT: A Framework for Security Risk Identification and Red Teaming in Generative AI System
von: Munoz, Gary D. Lopez, et al.
Veröffentlicht: (2024)
von: Munoz, Gary D. Lopez, et al.
Veröffentlicht: (2024)
CivicShield: A Cross-Domain Defense-in-Depth Framework for Securing Government-Facing AI Chatbots Against Multi-Turn Adversarial Attacks
von: Patil, KrishnaSaiReddy
Veröffentlicht: (2026)
von: Patil, KrishnaSaiReddy
Veröffentlicht: (2026)
Security and Privacy Challenges of Large Language Models: A Survey
von: Das, Badhan Chandra, et al.
Veröffentlicht: (2024)
von: Das, Badhan Chandra, et al.
Veröffentlicht: (2024)
A Case Study on the Impact of Anonymization Along the RAG Pipeline
von: Bodea, Andreea-Elena, et al.
Veröffentlicht: (2026)
von: Bodea, Andreea-Elena, et al.
Veröffentlicht: (2026)
Privacy Preserving Machine Learning Workflow: from Anonymization to Personalized Differential Privacy Budgets in Federated Learning
von: Díaz, Judith Sáinz-Pardo, et al.
Veröffentlicht: (2026)
von: Díaz, Judith Sáinz-Pardo, et al.
Veröffentlicht: (2026)
Searching for Privacy Risks in LLM Agents via Simulation
von: Zhang, Yanzhe, et al.
Veröffentlicht: (2025)
von: Zhang, Yanzhe, et al.
Veröffentlicht: (2025)
Exposing Privacy Risks in Graph Retrieval-Augmented Generation
von: Liu, Jiale, et al.
Veröffentlicht: (2025)
von: Liu, Jiale, et al.
Veröffentlicht: (2025)
Balancing Innovation and Privacy: Data Security Strategies in Natural Language Processing Applications
von: Liu, Shaobo, et al.
Veröffentlicht: (2024)
von: Liu, Shaobo, et al.
Veröffentlicht: (2024)
EmoRAG: Evaluating RAG Robustness to Symbolic Perturbations
von: Zhou, Xinyun, et al.
Veröffentlicht: (2025)
von: Zhou, Xinyun, et al.
Veröffentlicht: (2025)
SoK: Security and Privacy Risks of Healthcare AI
von: Chang, Yuanhaur, et al.
Veröffentlicht: (2024)
von: Chang, Yuanhaur, et al.
Veröffentlicht: (2024)
AVISE: Framework for Evaluating the Security of AI Systems
von: Lempinen, Mikko, et al.
Veröffentlicht: (2026)
von: Lempinen, Mikko, et al.
Veröffentlicht: (2026)
Privacy and Security Threat for OpenAI GPTs
von: Wenying, Wei, et al.
Veröffentlicht: (2025)
von: Wenying, Wei, et al.
Veröffentlicht: (2025)
IncogniText: Privacy-enhancing Conditional Text Anonymization via LLM-based Private Attribute Randomization
von: Frikha, Ahmed, et al.
Veröffentlicht: (2024)
von: Frikha, Ahmed, et al.
Veröffentlicht: (2024)
Shadow in the Cache: Unveiling and Mitigating Privacy Risks of KV-cache in LLM Inference
von: Luo, Zhifan, et al.
Veröffentlicht: (2025)
von: Luo, Zhifan, et al.
Veröffentlicht: (2025)
Backdoor Token Unlearning: Exposing and Defending Backdoors in Pretrained Language Models
von: Jiang, Peihai, et al.
Veröffentlicht: (2025)
von: Jiang, Peihai, et al.
Veröffentlicht: (2025)
SoK: Security and Privacy of AI Agents for Blockchain
von: Romandini, Nicolò, et al.
Veröffentlicht: (2025)
von: Romandini, Nicolò, et al.
Veröffentlicht: (2025)
A Practical Framework for Evaluating Medical AI Security: Reproducible Assessment of Jailbreaking and Privacy Vulnerabilities Across Clinical Specialties
von: Wang, Jinghao, et al.
Veröffentlicht: (2025)
von: Wang, Jinghao, et al.
Veröffentlicht: (2025)
The Sum Leaks More Than Its Parts: Compositional Privacy Risks and Mitigations in Multi-Agent Collaboration
von: Patil, Vaidehi, et al.
Veröffentlicht: (2025)
von: Patil, Vaidehi, et al.
Veröffentlicht: (2025)
Privacy Challenges and Solutions in Retrieval-Augmented Generation-Enhanced LLMs for Healthcare Chatbots: A Review of Applications, Risks, and Future Directions
von: Guan, Shaowei, et al.
Veröffentlicht: (2025)
von: Guan, Shaowei, et al.
Veröffentlicht: (2025)
Privacy-Preserving Retrieval-Augmented Generation with Differential Privacy
von: Koga, Tatsuki, et al.
Veröffentlicht: (2024)
von: Koga, Tatsuki, et al.
Veröffentlicht: (2024)
Security Risks Concerns of Generative AI in the IoT
von: Xu, Honghui, et al.
Veröffentlicht: (2024)
von: Xu, Honghui, et al.
Veröffentlicht: (2024)
AgentSOC: A Multi-Layer Agentic AI Framework for Security Operations Automation
von: Roy, Joyjit, et al.
Veröffentlicht: (2026)
von: Roy, Joyjit, et al.
Veröffentlicht: (2026)
LeakDojo: Decoding the Leakage Threats of RAG Systems
von: Zhang, Maosen, et al.
Veröffentlicht: (2026)
von: Zhang, Maosen, et al.
Veröffentlicht: (2026)
Securing RAG: A Risk Assessment and Mitigation Framework
von: Ammann, Lukas, et al.
Veröffentlicht: (2025)
von: Ammann, Lukas, et al.
Veröffentlicht: (2025)
PrivacyLens: Evaluating Privacy Norm Awareness of Language Models in Action
von: Shao, Yijia, et al.
Veröffentlicht: (2024)
von: Shao, Yijia, et al.
Veröffentlicht: (2024)
Explainable Machine Learning-Based Security and Privacy Protection Framework for Internet of Medical Things Systems
von: Si-ahmed, Ayoub, et al.
Veröffentlicht: (2024)
von: Si-ahmed, Ayoub, et al.
Veröffentlicht: (2024)
Ignore This Title and HackAPrompt: Exposing Systemic Vulnerabilities of LLMs through a Global Scale Prompt Hacking Competition
von: Schulhoff, Sander, et al.
Veröffentlicht: (2023)
von: Schulhoff, Sander, et al.
Veröffentlicht: (2023)
AI-Driven Anonymization: Protecting Personal Data Privacy While Leveraging Machine Learning
von: Yang, Le, et al.
Veröffentlicht: (2024)
von: Yang, Le, et al.
Veröffentlicht: (2024)
When Better Features Mean Greater Risks: The Performance-Privacy Trade-Off in Contrastive Learning
von: Sun, Ruining, et al.
Veröffentlicht: (2025)
von: Sun, Ruining, et al.
Veröffentlicht: (2025)
Supporting Artifact Evaluation with LLMs: A Study with Published Security Research Papers
von: Heye, David, et al.
Veröffentlicht: (2026)
von: Heye, David, et al.
Veröffentlicht: (2026)
Adversarial Intent is a Latent Variable: Stateful Trust Inference for Securing Multimodal Agentic RAG
von: Singh, Inderjeet, et al.
Veröffentlicht: (2026)
von: Singh, Inderjeet, et al.
Veröffentlicht: (2026)
P$^2$RAG: Efficient Privacy-Preserving RAG Service Supporting Arbitrary Top-$k$ Retrieval
von: Ming, Yulong, et al.
Veröffentlicht: (2026)
von: Ming, Yulong, et al.
Veröffentlicht: (2026)
Ähnliche Einträge
-
BaxBench: Can LLMs Generate Correct and Secure Backends?
von: Vero, Mark, et al.
Veröffentlicht: (2025) -
When AI Meets the Web: Prompt Injection Risks in Third-Party AI Chatbot Plugins
von: Kaya, Yigitcan, et al.
Veröffentlicht: (2025) -
Design and Implementation of a Secure RAG-Enhanced AI Chatbot for Smart Tourism Customer Service: Defending Against Prompt Injection Attacks -- A Case Study of Hsinchu, Taiwan
von: Shih, Yu-Kai, et al.
Veröffentlicht: (2025) -
GradingAttack: Exposing Security Vulnerabilities in LLM Based Educational Grading Agents
von: Li, Xueyi, et al.
Veröffentlicht: (2026) -
Guarding Your Conversations: Privacy Gatekeepers for Secure Interactions with Cloud-Based AI Models
von: Uzor, GodsGift, et al.
Veröffentlicht: (2025)