Salience Induction against Multi-Hop RAG Agents: Threat and Defense
Xingfu Zhou, Pengfei Wang, Yuan Zhou, Wei Xie, Xu Zhou
cs.CR, cs.CL
Submitted: 2026-07-20
Comments: 18 pages, 4 figures, 12 tables
License: http://arxiv.org/licenses/nonexclusive-distrib/1.0/
Terminology
Sources
- Phantom: General Backdoor Attacks on Retrieval Augmented Language Generation
- M3-Embedding: Multi-Linguality, Multi-Functionality, Multi-Granularity Text Embeddings Through Self-Knowledge Distillation
- TrojanRAG: Retrieval-Augmented Generation Can Be Backdoor Driver in Large Language Models
- Knowledge-Augmented Language Model Verification
- ToolLLM: Facilitating Large Language Models to Master 16000+ Real-world APIs
- Certifiably Robust RAG against Retrieval Corruption
- BadRAG: Identifying Vulnerabilities in Retrieval Augmented Generation of Large Language Models
- Chain-of-Thought Hijacking
- Universal and Transferable Adversarial Attacks on Aligned Language Models
Related papers
- SoK: AI-Augmented Binary Reversing
- Relaxed Sender Anonymity for CBDC Interbank Settlement: A Zero-Knowledge Approach on Permissioned EVM
- Calibration-Family Overfit: Why Trusted Sabotage Monitors Don't Transfer Across Lineages
- Efficient Fuzzy PSI under One-Sided Assumptions
- Sealing the Audit-Runtime Gap for LLM Skills
- Token Composition: A Graph Based on EVM Logs