Researchers have identified a new attack vector against multi-hop retrieval-augmented generation (RAG) agents, termed Salience Induction. This method manipulates the position, emphasis, or framing of true information to redirect agent reasoning, even without explicit instructions or content poisoning. The attack was demonstrated across various frontier models like GPT, Claude, Gemini, DeepSeek, and Qwen, and agent architectures such as ReAct and Reflexion. A proposed defense, Salience Normalization, significantly reduces the attack's success rate. AI
IMPACT Highlights a new vulnerability in AI agents that requires specialized defenses beyond content and instruction filtering.
RANK_REASON Academic paper detailing a new attack vector and defense for AI agents. [lever_c_demoted from research: ic=1 ai=1.0]
- Claude
- DeepSeek
- Gemini
- GPT
- Multi-Hop RAG Agents
- Qwen
- ReAct
- Salience Induction
- Salience Normalization
AI-generated summary · Google Gemini · from 1 sources. How we write summaries →