Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Awesome-RAG-Security — Curated collection of research papers on retrieval-augmented generation security, organized by the SLOT taxonomy covering knowledge poisoning, retrieval manipulation, context exploitation, and defenses. | Kitploit
Tools/GitHubGitHub/treeai-lab/awesome-rag-security
Vulnerability AnalysisThreat IntelligencePapers & ResearchLearning & EducationCurated ResourcesAI SecurityAdversarial Attack
GitHubtreeai-lab/awesome-rag-security

Awesome-RAG-Security

Curated collection of research papers on retrieval-augmented generation security, organized by the SLOT taxonomy covering knowledge poisoning, retrieval manipulation, context exploitation, and defenses.

View Repository
9141 month agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Awesome-RAG-Security

News

Initial release: This repository records papers on RAG security following the SLOT taxonomy from our survey.

A Survey of Secure Retrieval-Augmented Generation

Yuming Xu 1, Mingtao Zhang 1, Zhuohan Ge 1, Haoyang Li 1, Nicole Hu 1, Yongqi Zhang 2, Zhiyuan Wen 1, Jason Chen Zhang 1, Qing Li 1, Lei Chen 2

1The Hong Kong Polytechnic University, 2The Hong Kong University of Science and Technology (Guangzhou).

@article{xu2026securing,
  title={A Survey of Secure Retrieval-Augmented Generation},
  author={Xu, Yuming and Zhang, Mingtao and Ge, Zhuohan and Li, Haoyang and Hu, Nicole and Zhang, Yongqi and Wen, Zhiyuan and Zhang, Jason Chen and Li, Qing and Chen, Lei},
  journal={arXiv preprint arXiv:2604.08304},
  year={2026}
}

If you would like to include your paper, suggest improvements to our survey, or discuss related topics with us, please feel free to contact: [email protected].

Attack surfaces (S1-S4) and defense layers that mirror them (L1-L4) along the RAG pipeline.

Attack surfaces (S1-S4) and defense layers that mirror them (L1-L4) along the RAG pipeline.

SLOT view of the RAG knowledge-access pipeline

SLOT view of the RAG knowledge-access pipeline. Attack surfaces (S1-S4) and defense layers (L1-L4) are aligned with the pipeline stages, while Objective (O) and Target (T) are cross-cutting tags used to compare attacks, defenses, and benchmarks, i.e., SLOT Tag = Surface/Layer + Objective + Target.

Taxonomy and Papers

  • Awesome-RAG-Security
  • Attack Mechanisms
    • Knowledge Poisoning (S1)
    • Retrieval Result Manipulation (S2)
    • Retrieved-Context Exploitation (S3)
    • Private Knowledge Extraction (S4)
  • Defenses and Remediation Mechanisms
    • Knowledge-Base Integrity and Remediation (L1)
    • Retrieval-Time Access Hardening (L2)
    • Post-Retrieval Context Isolation (L3)
    • Access Control, Privacy and Confidentiality (L4)
  • Secure-RAG Evaluation Studies
    • Benchmark Studies
    • Systematic Evaluation Studies
  • Screening Protocol and Released Records

Attack Mechanisms

Knowledge Poisoning (S1)

Query-Specific Corpus Poisoning (To Top)

YearTitleSurface/LayerObjectiveTargetVenueOfficial Link
2026Practical Poisoning Attacks against Retrieval-Augmented Generation (CorruptRAG)S1; sec: S2O1T1SACMATPaper
2026RIPRAG: Hack a Black-box Retrieval-Augmented Generation Question-Answering System with Reinforcement LearningS1; sec: S2O1T1Findings of ACLPaper
2026Token-Level Precise Attack on RAG: Searching for the Best Alternatives to Mislead GenerationS1; sec: S2O1T1Findings of EACLPaper
2026Joint-GCG: Unified Gradient-Based Poisoning Attacks on Retrieval-Augmented Generation SystemsS1; sec: S2, S3O1T1AAAIPaper Code
2025The Silent Saboteur: Imperceptible Adversarial Attacks against Black-Box Retrieval-Augmented Generation SystemsS1; sec: S2O1T1Findings of ACLPaper Code
2025One Shot Dominance: Knowledge Poisoning Attack on Retrieval-Augmented Generation Systems (AuthChain)S1; sec: S2O1T1Findings of EMNLPPaper Code
2025The RAG Paradox: A Black-Box Attack Exploiting Unintentional Vulnerabilities in Retrieval-Augmented Generation SystemsS1; sec: S2O1T1Findings of EMNLPPaper
2025PoisonedRAG: Knowledge Corruption Attacks to Retrieval-Augmented Generation of Large Language ModelsS1; sec: S2O1T1USENIX SecurityPaper Code
2024Typos that Broke the RAG's Back: Genetic Attack on RAG Pipeline by Simulating Documents in the Wild via Low-Level Perturbations (GARAG)S1; sec: S2O1T1Findings of EMNLPPaper
2024Human-Imperceptible Retrieval Poisoning Attacks in LLM-Powered ApplicationsS1; sec: S3O1T1FSE CompanionPaper
2024HijackRAG: Hijacking Attacks against Retrieval-Augmented Large Language ModelsS1; sec: S2, S3O1T1arXivPaper Code

Trigger / Generalized Poisoning (To Top)

Download Tool