LATIDIA · Investigación
RAG-NAROK: Envenenamiento por corpus de conocimiento consciente de recuperación en RAG con refutación específica de la fuente
arXiv: 2609.25469v1Tipo de anuncio: nuevo Resumen: Los sistemas de generación aumentada de recuperación (RAG) se han convertido en la arquitectura dominante para basar las salidas del modelo de lenguaje grande (LLM) en conocimiento externo verificable, sí
WhatsApp ↗Telegram ↗
La noticia
arXiv:2609.25469v1 Announce Type: new Abstract: Retrieval augmented generation (RAG) systems have emerged as the dominant architecture for grounding large language model (LLM) outputs in verifiable external knowledge, yet their structural reliance on a dynamic retrieval pipeline introduces a largely unexplored class of adversarial vulnerability. Existing knowledge-base poisoning attacks are fundamentally static. Adversarial documents are pre-computed and injected without any awareness of what the victim system will actually retrieve for a given query, leaving the attack blind to the competitive documentary landscape that surrounds its payload in the generator's context window. Unlike traditional static poisoning attacks that are blind to the retrieved context, we introduce RAG-NAROK (Retrieval-Anchored Generation Negation And Response