Fetching from the wire…
Research2026-08-06 · source-backed
arXiv 2608.04756 observes that post-retrieval conflict resolution catches existing black-box poisoning because every prior method asserts its target answer in frontal contradiction to settled context. PURPOSE extracts query-related facts approximating the resolver's likely reference, then grounds a pivot event in them, framing the injection as a consistent update. Highest ASR in 35 of 45 settings across three QA benchmarks, five generators and three conflict-resolution methods, beating the strongest prior attack by a mean of 9.7 points. Conflict-detection defenses key on a contradiction signal the attacker can simply decline to emit.
Each link below shares sources, entities, or timing with this story.
arXiv 2608.00765 compresses retrieved docs into query-conditioned visual representations, sidestepping the trade-off where hard compression is query-aware but weak and soft compression is strong but needs costly offline encoding. Beats both baselines across varying retrieval d...
Existing RAG poisoning is filterable because the adversarial chunk contains the query. CamoDocs chunks synthesized benign and adversarial drafts, swaps selected tokens in benign chunks for dispersion tokens that spread the poisoned embeddings, then coherence-filters for readab...
Dahal and Xiong target injected documents that are individually benign but create false associations once aggregated, which is structurally invisible to any per-document filter (arXiv 2607.20437). TopoGuard builds a semantic similarity graph over the retrieved set and flags ma...
RAGAS-style evaluation checks correctness against a frozen snapshot, which means routine document updates and corrections can silently break production without moving a dashboard. This ASE 2026 paper defines 11 mutation operators perturbing at both the pre-chunk index level an...
Minghao Luo and Liang Chen's benchmark spans 225 real products across 15 categories, and every tested search-augmented LLM could be manipulated into recommending fake products (arXiv). A single polluted page yields fooled rates up to 27%; replacing the top-3 retrieved pages pu...
A new paper shows LLMs can be pushed toward misleading conclusions when fabricated "evidence" gets injected into context. No exploit, no jailbreak, just planted false context shifting the stated answer. Source: arXiv This is the threat model RAG builders keep underrating. Your...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.