paper-with-me

홈 › Papers

Tracing Target Answers in Poisoned Retrieval Corpora via Token Influence Attribution

2026-06-24 · Yan-Lun Chen, Pin-Yu Chen, Chia-Mu Yu, Ying-Dar Lin, Yu-Sung Wu, Wei-Bin Lee arxiv

Retrieval-Augmented Generation (RAG) systems are vulnerable to corpus poisoning attacks that manipulate model outputs through malicious retrieved documents. Existing detection methods typically rely on auxiliary classifiers or additional LLM-based verification, introducing substantial computational overhead. We present TRACE, a lightweight detection framework that identifies poisoning attacks by tracing answer-related tokens through token influence attribution. TRACE first discovers recurrent high-influence keywords across retrieved documents and then performs a secondary verification to confirm their influence on model predictions. Experiments on three QA benchmarks and six LLMs demonstrate strong detection performance while simultaneously uncovering attacker-specified target answers.

📄 PDF Abstract BibTeX arXiv:2606.25721

Code (0)

등록된 구현이 없습니다.

Similar Papers 제목 키워드 기반

KEPo: Knowledge Evolution Poison on Graph-based Retrieval-Augmented Generation

2026-03-12 · Qizhi Chen, Chao Qi, Yihong Huang, Muquan Li 외 arxiv

Graph-based Retrieval-Augmented Generation (GraphRAG) constructs the Knowledge Graph (KG) from external databases to enhance the timeliness and accuracy of Large Language Model (LLM) generations. However, this reliance o…

Data Extraction Attacks in Retrieval-Augmented Generation via Backdoors

2024-11-03 · Yuefeng Peng, Junda Wang, Hong Yu, Amir Houmansadr

Despite significant advancements, large language models (LLMs) still struggle with providing accurate answers when lacking domain-specific or up-to-date knowledge. Retrieval-Augmented Generation (RAG) addresses this limi…

Instruction FollowingRAGRetrievalRetrieval-augmented Generation

A Wolf in Sheep's Clothing: Targeted Routing Hijacking in Federated RAG

2026-05-27 · Junjie Mu, Qiongxiu Li arxiv

Federated Retrieval-Augmented Generation (FedRAG) is attractive for privacy-sensitive applications because full local corpora remain on clients. As a result, routing must rely on client-provided semantic profiles, creati…

Federated Learning

SilentRetrieval: Hijacking Retrieval-Augmented Generation via Semantically-Preserving Adversarial Data Poisoning

2026-05-27 · Jiachen Qian arxiv

Retrieval-Augmented Generation (RAG) mitigates LLM hallucinations but introduces a critical vulnerability: corpus integrity. We present SilentRetrieval, a two-stage data poisoning attack that hijacks RAG systems through …

Natural Questions

CamoDocs: A Poisoning Attack Against Retrieval-Augmented Language Models Using Camouflaged Documents

2026-08-28 · Jaewon Jung, Haizhong Zheng, Hongsun Jang, Jaeyong Song 외 arxiv

Retrieval-augmented generation (RAG) augments LLMs with external documents, but public or user-editable sources expose RAG systems to data poisoning: attackers can inject malicious documents to steer outputs toward targe…