Fetching from the wire…
Security2026-07-26 · source-backed
Dahal and Xiong target injected documents that are individually benign but create false associations once aggregated, which is structurally invisible to any per-document filter (arXiv 2607.20437). TopoGuard builds a semantic similarity graph over the retrieved set and flags malicious topology. The λ₂+Entity variant hits 32.6% recall versus LlamaGuard's 1.5% at 1% FPR on HotpotQA. Because it scores the context as a graph instead of calling a model, it drops in front of an existing retriever with no LLM hop added.
Each link below shares sources, entities, or timing with this story.
Simon Willison released LLM / Shared entity: RAG / Shared topic / Earlier coverage
Linked by a graph relationship (Simon Willison released LLM); both cover RAG; overlapping topics (context, drop).
Simon Willison released LLM / Shared entity: LLM / Earlier coverage / Tension
Linked by a graph relationship (Simon Willison released LLM); both cover LLM; earlier LLM coverage from 2026-06-19.
Linked by a graph relationship (Simon Willison released LLM); both cover LLM; earlier LLM coverage from 2026-06-18.
Simon Willison released LLM / Shared entity: LLM / Earlier coverage
Linked by a graph relationship (Simon Willison released LLM); both cover LLM; earlier LLM coverage from 2026-06-19.
Linked by a graph relationship (Simon Willison released LLM); both cover LLM; earlier LLM coverage from 2026-07-19.
Linked by a graph relationship (Simon Willison released LLM); both cover LLM; earlier LLM coverage from 2026-07-14.
Linked by a graph relationship (Simon Willison released LLM); both cover LLM; earlier LLM coverage from 2026-06-22.
Linked by a graph relationship (Simon Willison released LLM); both cover LLM; earlier LLM coverage from 2026-06-10.