Retrieved But Not Reliable: A Survey on Attacks, and Defenses in Retrieval-Augmented Generation
cs.CR, cs.CL, cs.LG
Submitted: 2026-08-25
Updated: 2026-08-27
Code: https://github.com/coutMinh/A-Survey-on-RAG-Robustness
Terminology
Sources
- Do Multimodal RAG Systems Leak Data? A Comprehensive Evaluation of Membership Inference and Image Caption Retrieval Attacks
- Detecting Language Model Attacks with Perplexity
- What External Knowledge is Preferred by LLMs? Characterizing and Exploring Chain of Evidence in Imperfect Context for Multi-Hop QA
- Rethinking All Evidence: Enhancing Trustworthy Retrieval-Augmented Generation via Conflict-Driven Summarization
- Uncovering Competing Poisoning Attacks in Retrieval-Augmented Generation
- Evaluating Large Language Models Trained on Code
- Scalable Defense against In-the-wild Jailbreaking Attacks with Safety Context Retrieval
- Eyes-on-Me: Scalable RAG Poisoning through Transferable Attention-Steering Attractors
- Fine-Grained Privacy Extraction from Retrieval-Augmented Generation Systems via Knowledge Asymmetry Exploitation
- Black-Box Opinion Manipulation Attacks to Retrieval-Augmented Generation of Large Language Models
- TrojanRAG: Retrieval-Augmented Generation Can Be Backdoor Driver in Large Language Models
- Secure Retrieval-Augmented Generation against Poisoning Attacks
- Recent Advances in Attack and Defense Approaches of Large Language Models
- After Retrieval, Before Generation: Enhancing the Trustworthiness of Large Language Models in Retrieval-Augmented Generation
- From Local to Global: A Graph RAG Approach to Query-Focused Summarization
- Collapse of Dense Retrievers: Short, Early, and Literal Biases Outranking Factual Evidence
- UniC-RAG: Universal Knowledge Corruption Attacks to Retrieval-Augmented Generation
- Topic-FlipRAG: Topic-Orientated Adversarial Opinion Manipulation Attacks to Retrieval-Augmented Generation Models
- MM-PoisonRAG: Disrupting Multimodal RAG with Local and Global Poisoning Attacks
- RAGRank: Using PageRank to Counter Poisoning in CTI LLM Pipelines
Related papers
- SoK: AI-Augmented Binary Reversing
- Relaxed Sender Anonymity for CBDC Interbank Settlement: A Zero-Knowledge Approach on Permissioned EVM
- Calibration-Family Overfit: Why Trusted Sabotage Monitors Don't Transfer Across Lineages
- Efficient Fuzzy PSI under One-Sided Assumptions
- Sealing the Audit-Runtime Gap for LLM Skills
- Token Composition: A Graph Based on EVM Logs