🤖 AI Summary
This study addresses the structured attack surfaces and risk assessment challenges introduced by multi-stage pipelines in Retrieval-Augmented Generation (RAG) systems. To this end, it proposes a security metamodel framework that integrates explicit causal correlations. Through iterative structured literature analysis and knowledge graph modeling, the metamodel is instantiated into a navigable threat catalog, enabling deployment configuration-based risk profiling and interactive visualization. This work bridges critical gaps in RAG offense-defense asymmetry and output integrity coverage. Furthermore, its applicability is validated across text, graph, and multimodal configurations, demonstrating significant improvements in risk identification efficiency for security engineers.
📝 Abstract
Retrieval-Augmented Generation (RAG) systems extend large language models (LLMs) with external knowledge through a multi-stage pipeline. While this architecture can improve the factual grounding of generated answers, it introduces structural attack surfaces that extend beyond those of standalone LLMs. In this paper, we introduce a security meta-model that captures explicit causal relationships between RAG surfaces, attacks, weaknesses, risks, and CIA impact (Confidentiality, Integrity, Availability). Its purpose is to provide security engineers with a structured and user-friendly framework for gathering and assessing the risks, weaknesses, and mitigations relevant to their RAG deployment. We designed the meta-model through an iterative, structured analysis of 43~publications (2023--2026) and instantiated it as a catalog populated with the security threats and remediations reported in the literature. Filtering the catalog according to a deployment configuration produces a risk profile containing the risks applicable to that deployment. An interactive web visualizer lets users navigate the catalog as a graph, follow causal chains, and explore stakeholder-specific views. Analysis of the catalog revealed a persistent imbalance between attack-focused and defense-focused research, a concentration of threats at ingestion, and coverage gaps affecting output integrity. Coverage is assessed against the OWASP LLM Top~10, and operational applicability is illustrated across textual, graph-based, and multimodal RAG configurations.