Researchers have identified a new type of attack called RAG poisoning, which targets the knowledge base of Retrieval-Augmented Generation (RAG) systems during the indexing phase, rather than at query time like prompt injection. This method allows attackers to embed malicious content into a system's data store, such as Microsoft 365 Copilot, leading to widespread misinformation or manipulation. Studies have shown that even a small number of poisoned documents can significantly impact large knowledge bases, and existing defenses are insufficient to prevent these attacks. AI
IMPACT Highlights a critical new vulnerability in RAG systems, necessitating new security paradigms beyond prompt injection defenses.
RANK_REASON The item details a new security vulnerability and attack vector for LLM systems, supported by multiple research papers and demonstrations. [lever_c_demoted from research: ic=1 ai=1.0]
- AgentPoison
- ConfusedPilot
- Greshake et al.
- Microsoft Copilot for Microsoft 365
- Microsoft SharePoint
- NeurIPS 2024
- OWASP
- PoisonedRAG
- RAG Poisoning
- Usenix Security 2025
- Wei Zou
AI-generated summary · Google Gemini · from 1 sources. How we write summaries →