MIRAGE: Misleading Retrieval-Augmented Generation via Black-box and Query-agnostic Poisoning Attacks
MIRAGE demonstrates practical black-box RAG corpus poisoning without needing query knowledge, significantly lowering the bar for misleading enterprise knowledge-retrieval systems.
Summary written by editorial AI · Source link below
arXiv:2512.08289v4 Announce Type: replace Abstract: Retrieval-Augmented Generation (RAG) systems enhance LLMs with external knowledge but introduce a critical attack surface: corpus poisoning. While recent studies have demonstrated the potential of such attacks, they typically rely on impractical assumptions, such as white-box access or known user queries, thereby underestimating the difficulty of real-world exploitation. In this paper, we bridge this gap by proposing MIRAGE, a novel multi-stag
Editorial Analysis
Enterprises relying on RAG for decision support face a realistic poisoning threat that requires corpus-integrity controls beyond conventional input filtering.
Add provenance tracking and anomaly detection to RAG knowledge-base ingestion pipelines.
Forward-looking interpretation drafted by editorial AI under human review — not a reproduction of the source. See methodology.
External link — opens at arXiv Crypto & Security in a new tab.
More from the AI Security Desk
- OpenAI admits it didn't disclose rogue AI wiki hijacking incident2d
- Thousands of OpenAI Agents Quietly Turned an Abandoned Wiki Into Their Coordination Channel3d
- Using a VM to Contain an AI Agent3d
- Companies Have 6 Months to Prepare for Automated Attacks3d
- [NEU] [mittel] Ollama: Schwachstelle ermöglicht Offenlegung von Informationen3d