Backdoor in the Loop: Compromising Agentic Search via Malicious Retrievers
cs.CR, cs.AI, cs.IR, cs.LG
Submitted: 2026-09-26
Updated: 2026-09-26
Terminology
Sources
- Detecting Backdoor Attacks on Deep Neural Networks by Activation Clustering
- AgentIR: Reasoning-Aware Retrieval for Deep Research Agents
- TrojanRAG: Retrieval-Augmented Generation Can Be Backdoor Driver in Large Language Models
- Backdoored Retrievers for Prompt Injection Attacks on Retrieval Augmented Generation of Large Language Models
- DisarmRAG: Stealthy Retriever-Centric Poisoning to Disable Self-Correction in Retrieval-Augmented Generation (Extended Version)
- Semantics Delivery Network: Rethinking Web Retrieval Infrastructure for LLM Agents
- Dummy Backdoor as a Defense: Removing Unknown Backdoors via Shared Internal Mechanisms for Generative LLMs
- Search-R1: Training LLMs to Reason and Leverage Search Engines with Reinforcement Learning
- Conflict-Aware Retriever Editing for Knowledge Injection Attacks on LLM-Based RAG Systems
- WebGPT: Browser-assisted question-answering with human feedback
- JailDAM: Jailbreak Detection with Adaptive Memory for Vision-Language Model
- BackFlush: Knowledge-Free Backdoor Detection and Elimination with Watermark Preservation in Large Language Models
- R1-Searcher: Incentivizing the Search Capability in LLMs via Reinforcement Learning
- Text Embeddings by Weakly-Supervised Contrastive Pre-training
Related papers
- SoK: AI-Augmented Binary Reversing
- Relaxed Sender Anonymity for CBDC Interbank Settlement: A Zero-Knowledge Approach on Permissioned EVM
- Calibration-Family Overfit: Why Trusted Sabotage Monitors Don't Transfer Across Lineages
- Efficient Fuzzy PSI under One-Sided Assumptions
- Sealing the Audit-Runtime Gap for LLM Skills
- Token Composition: A Graph Based on EVM Logs