Fetching from the wire…
Research2026-09-16 · source-backed
InceptionRAG fragments the payload into a chain of dormant passages, each benign under isolated inspection, that lead the model to self-deduce the target misinformation through multi-hop reasoning when retrieved together. Across three datasets and three LLMs it exceeds 80% ASR under adversarial constraints while bypassing defenses built for single-document injection. The authors state the paradox plainly: stronger reasoning increases vulnerability. Their proposed HODOR defense decouples the adversarial logical dependencies.
Each link below shares sources, entities, or timing with this story.
arXiv 2607.24174 (July 27) generated adversarial log entries from real attack traces and got multiple state-of-the-art LLMs to classify traces containing clear indicators of compromise as benign. The defensive gift: the natural-language explanations emitted alongside the class...
Counter-GEO-Bench pairs 247 human-verified queries with matched information-preserving and information-distorting rewrites, scoring defenses across three victim LLMs. Granite Guardian, Llama Guard 3 and NeMo Self-Check Fact-Checking reduced attack success by at most 5.7% relat...
arXiv 2608.00765 compresses retrieved docs into query-conditioned visual representations, sidestepping the trade-off where hard compression is query-aware but weak and soft compression is strong but needs costly offline encoding. Beats both baselines across varying retrieval d...
Existing RAG poisoning is filterable because the adversarial chunk contains the query. CamoDocs chunks synthesized benign and adversarial drafts, swaps selected tokens in benign chunks for dispersion tokens that spread the poisoned embeddings, then coherence-filters for readab...
D-SCAN (SIGIR 2026) found the standard guardrail returns high confidence on compromised output. Their alternative signal is document-level attention dynamics: during a poisoned generation, attention concentrates on the injected document and entropy collapses, versus dispersed...
1. Flip your multi-model pipeline to review-then-generate. Instead of using a reasoning model to plan before code generation, let the specialist generate freely and use reasoning tokens for review. Paper shows 90.2% pass@1 vs 87.2% for the planning pattern. Source 2. Audit you...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.