Micro-Collaborative Poisoning: A Distributed Attack on RAG Systems

📅 2026-09-18
📈 Citations: 0
Influential: 0
📄 PDF
🤖 AI Summary
研究针对RAG系统的分布式攻击,通过在多个文档中分散虚假信息而非集中于一处,评估了不同配置下的攻击效果及防御策略。
📝 Abstract
Retrieval-Augmented Generation (RAG) improves large language models by grounding outputs in external knowledge sources, but this dependency also creates a surface for poisoning attacks. This paper introduces Micro-Collaborative Poisoning, a distributed attack in which a false target claim is divided across multiple locally plausible documents instead of being concentrated in a single malicious passage. We evaluate the attack across 108 RAG configurations by varying dataset, retriever architecture, retrieval depth, database composition, number of poisoned databases, and generator model. The results indicate that Micro-Collaborative Poisoning is not driven by a single dominant poisoned passage, but by the accumulation of weak adversarial signals across retrieved sources. Increasing top-$k$ and poisoning multiple databases make it more likely that these signals will appear together in the retrieved context, while clean database diversity and stronger retrievers can reduce their influence. The document-level poisoning visibility analysis further shows that this threat is difficult to expose through isolated document inspection, since Micro-Collaborative Poisoning achieves downstream influence while leaving a weaker explicit poisoning signature than direct poisoning.
Problem

Research questions and friction points this paper is trying to address.

Micro-Collaborative Poisoning
RAG Systems
Distributed Attack
External Knowledge Sources
Poisoning Attacks
Innovation

Methods, ideas, or system contributions that make the work stand out.

Micro-Collaborative Poisoning
Distributed Attack
RAG Systems
External Knowledge Sources
Poisoning Attacks
🔎 Similar Papers
💼 Related Jobs
No related jobs found.
P
Pedro Pereira
GECAD, ISEP, Polytechnic of Porto, Rua Dr. António Bernardino de Almeida, 4249-015 Porto, Portugal
Eva Maia
Eva Maia
GECAD-ISEP
CyberSecurityArtificial InteligenceMachine LearningIndustry 4.0Encryption
Isabel Praça
Isabel Praça
Professor, ISEP