A Security Meta-Model for Retrieval-Augmented Generation Systems

arXiv:2610.11893 · cs.CR · Submitted 2026-10-08 · Read on arXiv

Listen

Radio episode about this paper

Transcript

Introduction to the show: ident: Security Radio. Generated commentary on the latest security and cryptography papers.

Nadia: Today's paper: "A Security Meta-Model for Retrieval-Augmented Generation Systems".

Elias: The gist The authors introduce a security meta-model that captures explicit causal relationships between Retrieval-Augmented Generation (RAG) surfaces, attacks, weaknesses, risks,

Nadia: First, who's behind it and why it matters.

Title and authors: Nadia: We’re looking at the title "A Security Meta-Model for Retrieval-Augmented Generation Systems" and the authors, Steve Nouyep, Sébastien Salva, and Maxime Puys. The title tells us immediately that they are creating a framework to organize all the security aspects of RAG systems.

Elias: It’s not just about listing problems; it's about capturing the explicit causal relationships between surfaces and attacks and the resulting CIA impact—Confidentiality, Integrity, Availability.

Priya: So when we talk about RAG systems, we aren't just talking about a chatbot anymore; we are talking about a pipeline where every stage introduces new security concerns that need mapping.

Nadia: Right. They designed this meta-model to be a structured and user-friendly framework specifically for security engineers who are trying to gather and assess risks relevant to their RAG deployments.

Elias: The authors did this by taking an iterative, structured analysis of forty-three publications from two thousand twenty-three to two thousand twenty-six and building a catalog populated with all the security threats and remediations they found in that literature <ref:2610.11893#pg1,an iterative, structured analysis of 43 publications>.

Priya: That means the foundation isn't built on just one paper or one attack type; it’s synthesized from a broad sweep of recent research over several years.

Nadia: Exactly. And they grounded the extraction of entities and relations using established identifiers like CWE and CAPEC, which ties their findings directly to recognized vulnerability standards.

Elias: The goal there is to move past individual studies that might look at one aspect in isolation and build something that connects everything systematically across different RAG system types.

Priya: I think the key thing here is the breadth of input they used; they didn't just look at the obvious RAG attacks, but they pulled from a wide range of existing security research.

The paper's summary: Nadia: So looking at what the paper summarizes, it’s this idea that RAG systems introduce structural attack surfaces that are different from standalone LLMs because of how they pull in external knowledge.

Elias: They summarized the core concept as introducing a security meta-model to capture those explicit causal relationships between RAG surfaces, attacks, weaknesses, risks, and CIA impact.

Priya: Essentially, they’ve mapped out the whole lifecycle of a potential security issue in a RAG context—from what part of the system is vulnerable to what kind of attack it enables and what that ultimately compromises.

Nadia: They describe this as providing security engineers with a structured view for gathering and assessing risks, weaknesses, and mitigations relevant to their specific RAG deployment.

Elias: The core mechanism they use is defining the structure through a triple M—Entity, Relation, Constraint—to ensure that the links between these elements are logically sound and consistent.

Priya: It sounds like they’ve built a comprehensive dictionary of how things connect, making it easier to see not just *what* the threats are but *why* they matter for the system's safety.

Nadia: That’s right. They show how RAG type leads to a surface, which allows an attack, which exploits a weakness, and that ultimately generates a risk that affects Confidentiality, Integrity, or Availability.

Elias: It’s about creating this coherent view that links the architecture of the RAG system directly to its overall security posture concerning those three core dimensions.

The paper's improvements: Nadia: Now let's talk about what they suggest improving, because it’s not just a static catalog; they have specific mechanisms for making this catalog useful.

Elias: One major improvement is the context-dependent filtering mechanism, which uses six deployment properties to dynamically label each risk as eliminated, mitigated, aggravated, or normal based on the system's actual configuration.

Priya: That’s a big deal because it means you don't have to filter a thousand risks; you can instantly narrow down the profile to only what applies right now.

Nadia: Right. They also built four complementary taxonomic views—Architect, CISO, Pentester, and DPO—to tailor the information presented for different stakeholders.

Elias: For instance, the CISO view helps them see exactly which mitigations exist and where the coverage gaps are in their defense strategies across all those entities.

Priya: And for the DPO, that view allows them to reason directly in terms of data assets and CIA impact rather than getting stuck chasing technical attack chains.

Nadia: They also mentioned strengthening structural consistency by enforcing four programmatic constraints: every attack must link to at least one surface, one weakness, and one risk.

Elias: That's a strong move because it ensures that no matter how big the catalog gets, the fundamental logic—that an attack needs an entry point and a vulnerability to work—stays intact.

Conclusion: Nadia: So to wrap up, this paper introduces the Security Meta-Model for Retrieval-Augmented Generation Systems as a structured way to assess RAG deployment risks by explicitly linking architecture to CIA impact through a causal chain.

Elias: It successfully bridges RAG threats with standardized identifiers while adapting the assessment dynamically based on how you configure your specific system.

Priya: The real practical value, as I see it, is that this framework turns a massive catalog into a deployment-specific risk profile using that context filtering algorithm.

Nadia: Exactly. And by giving us those four stakeholder views and the structural constraints, they’ve created something that helps security teams understand the landscape much more clearly than before.

Elias: The authors also flag some limitations, specifically mentioning that they need to re-evaluate mitigations because their effectiveness hasn't been fully validated in real-world operational settings yet.

Priya: That’s fair; theory is one thing, but proving a mitigation works under actual stress is the next hurdle we have to clear.

Nadia: The path forward they suggest involves closing those coverage gaps and empirically validating the mitigations on production deployments with actual practitioners involved in testing the views.

Elias: So, in short, this paper systematizes documented attacks into a coherent model that lets us see the whole chain and then use context to focus our attention on what matters most for our current setup.

Steve Nouyep, Sébastien Salva, Maxime Puys

Université Clermont Auvergne · CNRS

cs.CR

Submitted: 2026-10-08

Updated: 2026-10-08

License: http://creativecommons.org/licenses/by-sa/4.0/

The gist: The gist The authors introduce a security meta-model that captures explicit causal relationships between Retrieval-Augmented Generation (RAG) surfaces, attacks, weaknesses, risks, and CIA impact to

Key concepts

Meta-Model (M = E, R, C)
This is a structured framework where 'E' represents entities like RAG or Attack, 'R' defines the directed relationships between them (e.g., 'exploits'), and 'C' are structural constraints ensuring logical consistency. It creates a formal map of how different security elements interact within an RAG system.
Structural Specification (Causal Chain)
The model enforces a specific causal sequence: RAG surfaces expose things that enable attacks, which exploit weaknesses to generate risks, ultimately affecting the CIA. This constraint ensures that every attack is linked back to a surface and a weakness, providing a traceable path from architecture to impact.
Context-Dependent Risk Filtering
This mechanism uses six deployment properties (P1-P6) like 'ELIMINATES' or 'MITIGATES' to adjust the risk profile for specific deployments. This allows users to filter the large catalog of risks down to a configuration-specific view, showing only what is relevant based on how the system is actually set up.
Taxonomic Views
The model offers four different views tailored for specific roles: Architect, CISO, Pentester, and DPO. Each view shows only the entities and relations relevant to that role. This helps different stakeholders quickly find the security information they need without being overwhelmed by irrelevant details.

Terminology

Summary

The gist The authors introduce a security meta-model that captures explicit causal relationships between Retrieval-Augmented Generation (RAG) surfaces, attacks, weaknesses, risks, and CIA impact to provide a structured framework for assessing RAG deployment risks.

How it works

The meta-model is designed as an entity–relationship style model defined by a triple M = (E, R, C), where E is the set of entity types (RAG, Surface, Attack, Weakness, Risk, Mitigation, CIA), R is the set of directed relation types linking them (e.g., exposes; exploits; mitigates), and C is the set of structural constraints that valid instances must satisfy > 4. Structural specification follows a causal chain where a RAG system exposes surfaces which enable attacks which exploit weaknesses and generate risks, which affect CIA dimensions, with mitigations mitigating risks and remediating weaknesses > 10.

The construction of this catalog involved an iterative taxonomy method applied to 43 publications from 2023–2026 > 8. The process began by defining a meta-characteristic linking each RAG architectural surface to its CIA impact through a causal chain, which was then refined against the corpus > 4.1 Iterative Construction of the Meta-Model. Entity and relation extraction were grounded in CWE and CAPEC identifiers, and eight integration rules (IR1–IR8) specify how links between entities are constructed when populating the meta-model > 4.4 Security Data Integration and Catalog. These rules ensure structural consistency by requiring that every attack must be enabled by at least one Surface, exploit at least one Weakness, and generate at least one Risk > 4.3 Causal chain.

Key Components of the Model

The meta-model instantiates a catalog containing 3 RAG categories, 8 attack surfaces, 38 attacks, 12 weaknesses, 41 risks, and 72 mitigations > Page 2. The attacks are categorized into five groups: Poisoning (16), Exfiltration (11), Inference (5), Injection (4), and Degradation (2) > Table 4. Each risk is characterized by an attack, an affected asset, and one or more CIA dimensions, across five assets: CORPUS, OUTPUT, MEMBERSHIP, EMBEDDINGS, and PROMPTS > Page 12. The mitigations are classified following ISO 27001 and NIST CSF into preventive (43), detective (20), and reactive (9) measures > Page 12.

Context-Dependent Risk Filtering

A crucial feature is the context-dependent filtering mechanism, which uses six deployment properties (P1–P6) to produce a configuration-specific risk profile > 5.2 Views Related to Context. These properties determine risk applicability through effects such as ELIMINATES, MITIGATES, AGGRAVATES, or ADDS > Table 6. For example, the property type ≠ GRAPHRAG eliminates R17 because the system does not use knowledge-graph indexing > Page 14. This filtering distinguishes structural risks by labeling each risk as eliminated, mitigated, aggravated, or normal based on the deployment configuration > Page 14.

Stakeholder Views and Visualization

The meta-model supports four complementary taxonomic views tailored to distinct stakeholder roles: Architect (V1), CISO (V2), Pentester (V3), and DPO (V4) > Table 7. These views are projected subgraphs that retain only the entity types and relations relevant to a given role, such as V1 focusing on the chain RAG → Surface → Attack → Weakness ← Mitigation > Page 16. An interactive web visualizer operationalizes this by rendering the catalog as a navigable graph, allowing users to follow causal chains, apply context-related filtering interactively, and project the four stakeholder views > 5.1 The Interactive Web Visualizer.

Cross-Cutting Observations

Analysis of the catalog revealed persistent imbalances between attack-focused and defense-focused research, with 72% being attack papers versus 21% defense papers > Table 9. A significant finding is that ingestion control is a structural hotspot, as Surface S-DOC concentrates 16 of 38 attacks (42%), and open ingestion configurations are particularly exposed to integrity threats > Page 18. Furthermore, the OUTPUT asset exhibits the highest gap ratio (25%) for risks R34, R35, and R36, indicating a coverage gap in output integrity risks across all RAG types > Table 9.

Conclusion

The work presents a structurally specified security meta-model that integrates an explicit causal chain from architecture to CIA impact, bridges RAG-specific threats to standardized weakness and attack-pattern identifiers (CWE/CAPEC), and adapts to deployment context through property-based risk filtering > Page 20. Its practical value lies in the filtering algorithm turning a large catalog into a deployment-specific risk profile, the four taxonomic views letting each stakeholder reach the information relevant to their role, and the structural constraints enforcing consistency as the catalog grows > Page 20. The authors suggest three directions for future work: closing persistent coverage gaps, re-evaluating mitigations whose effectiveness remains unvalidated, and empirically validating the meta-model on production deployments with practitioner evaluation of the views > Page 19. This work systematizes publicly documented attacks; no new exploit is developed > Page 20. The authors provide a full catalog overview and regeneration scripts in supplementary material > Supplementary Material. The paper was supported by the Industrial Chair on Reliable and Confident Use of LLMs1 and by the MIAI Cluster, France 2030 (ANR-23-IACL-0006) > Page 21. The authors provide a full catalog overview and regeneration scripts in supplementary material > Supplementary Material. The paper was supported by the Industrial Chair on Reliable and Confident Use of LLMs1 and by the MIAI Cluster, France 2030 (ANR-23-IACL-0006) > Page 21. The authors provide a full catalog overview and regeneration scripts in supplementary material > Supplementary Material. The paper was supported by the Industrial Chair on Reliable and Confident Use of LLMs1 and by the MIAI Cluster, France 2030 (ANR-23-IACL-0006) > Page 21. The authors provide a full catalog overview and regeneration scripts in supplementary material > Supplementary Material. The paper was supported by the Industrial Chair on Reliable and Confident Use of LLMs1 and by the MIAI Cluster, France 2030 (ANR-21).

Page 1</ref:2610.11893

Page 5</ref:4

Page 5</ref:6

Page 7</ref:23

Page 7</ref:8

Page 10</ref:10

Page 10</ref:9

Page 4</ref:26

Page 8</ref:43

Page 8</ref:27

Page 15</ref:17

Page 9</ref:30

Page 9</ref:5

Page 9</ref:4.1

Page 10</ref:4.2

Page 6</ref:6.1

Page 7</ref:5.3

Page 5</ref:5.2

Page 13</ref:7

Page 11</ref:4.4

Page 18</ref:6.3

Page 9</ref:20

Page 5</ref:800-30

Page 17</ref:CWE-1427/94; S-GEN R9, R10 Full

Page 17</ref:EXF/INF CWE-200/212 R2, R4–R7 Full

Page 17</ref:POI S-DOC; CWE-345 R8, R11 Part.

Improvements for AI systems

  1. Improve system design by implementing context-dependent filtering to dynamically label risks based on deployment configurations, as shown in Algorithm 1 which assigns labels such as eliminated, mitigated, aggravated, or normal. This allows the system to produce a risk profile containing only the risks applicable to that specific deployment configuration.

  2. Enhance security posture by enabling four complementary taxonomic views for distinct stakeholder roles (Architect, CISO, Pentester, DPO). The CISO view can identify which mitigations exist and where are the coverage gaps, while the DPO view allows reasoning directly in terms of data assets and CIA impact rather than technical attack chains.

  3. Strengthen structural consistency by enforcing four programmatic constraints: every attack must be linked to at least one surface (C1), one weakness (C2), and one risk (C3), and every risk must affect at least one CIA dimension (C4). This ensures that the catalog remains structurally sound as new threats are added.

  4. Improve attack detection by integrating CWE/CAPEC identifiers into the catalog, allowing for traceability to standardized weakness and attack-pattern identifiers. This enables linking attacks to specific vulnerabilities like INJ maps to CWE-1427/74/693/863.

  5. Enhance risk prioritization by using the interactive web visualizer, which allows users to follow causal chains from surfaces to CIA impact and switch between role-related views. This enables practitioners to prioritize analysis based on their specific needs, such as the DPO needing information on for a given asset, which risks apply and what mitigations exist.

Abstract

Retrieval-Augmented Generation (RAG) systems extend large language models (LLMs) with external knowledge through a multi-stage pipeline. While this architecture can improve the factual grounding of generated answers, it introduces structural attack surfaces that extend beyond those of standalone LLMs. In this paper, we introduce a security meta-model that captures explicit causal relationships between RAG surfaces, attacks, weaknesses, risks, and CIA impact (Confidentiality, Integrity, Availability). Its purpose is to provide security engineers with a structured and user-friendly framework for gathering and assessing the risks, weaknesses, and mitigations relevant to their RAG deployment. We designed the meta-model through an iterative, structured analysis of 43 publications (2023--2026) and instantiated it as a catalog populated with the security threats and remediations reported in the literature. Filtering the catalog according to a deployment configuration produces a risk profile containing the risks applicable to that deployment. An interactive web visualizer lets users navigate the catalog as a graph, follow causal chains, and explore stakeholder-specific views. Analysis of the catalog revealed a persistent imbalance between attack-focused and defense-focused research, a concentration of threats at ingestion, and coverage gaps affecting output integrity. Coverage is assessed against the OWASP LLM Top 10, and operational applicability is illustrated across textual, graph-based, and multimodal RAG configurations.

Sources

Related papers