
Colección curada de artículos de investigación sobre seguridad en la generación aumentada por recuperación, organizada según la taxonomía SLOT que abarca envenenamiento de conocimiento, manipulación de recuperación, explotación de contexto y defensas.
Versión inicial: Este repositorio recopila artículos sobre seguridad en RAG siguiendo la taxonomía SLOT de nuestra encuesta.
Yuming Xu 1, Mingtao Zhang 1, Zhuohan Ge 1, Haoyang Li 1, Nicole Hu 1, Yongqi Zhang 2, Zhiyuan Wen 1, Jason Chen Zhang 1, Qing Li 1, Lei Chen 2
1The Hong Kong Polytechnic University, 2The Hong Kong University of Science and Technology (Guangzhou).
@article{xu2026securing,
title={A Survey of Secure Retrieval-Augmented Generation},
author={Xu, Yuming and Zhang, Mingtao and Ge, Zhuohan and Li, Haoyang and Hu, Nicole and Zhang, Yongqi and Wen, Zhiyuan and Zhang, Jason Chen and Li, Qing and Chen, Lei},
journal={arXiv preprint arXiv:2604.08304},
year={2026}
}
Si desea incluir su artículo, sugerir mejoras a nuestra encuesta o discutir temas relacionados con nosotros, no dude en ponerse en contacto: [email protected].
Superficies de ataque (S1-S4) y capas de defensa que las reflejan (L1-L4) a lo largo del pipeline de RAG.
Vista SLOT del pipeline de acceso al conocimiento de RAG. Las superficies de ataque (S1-S4) y las capas de defensa (L1-L4) están alineadas con las etapas del pipeline, mientras que Objetivo (O) y Objetivo (T) son etiquetas transversales utilizadas para comparar ataques, defensas y benchmarks, es decir, Etiqueta SLOT = Superficie/Capa + Objetivo + Objetivo.
| Año | Título | Superficie/Capa | Objetivo | Objetivo | Venue | Enlace Oficial |
|---|---|---|---|---|---|---|
| 2026 | Practical Poisoning Attacks against Retrieval-Augmented Generation (CorruptRAG) | S1; sec: S2 | O1 | T1 | SACMAT | Paper |
| 2026 | RIPRAG: Hack a Black-box Retrieval-Augmented Generation Question-Answering System with Reinforcement Learning | S1; sec: S2 | O1 | T1 | Findings of ACL | Paper |
| 2026 | Token-Level Precise Attack on RAG: Searching for the Best Alternatives to Mislead Generation | S1; sec: S2 | O1 | T1 | Findings of EACL | Paper |
| 2026 | Joint-GCG: Unified Gradient-Based Poisoning Attacks on Retrieval-Augmented Generation Systems | S1; sec: S2, S3 | O1 | T1 | AAAI | Paper Code |
| 2025 | The Silent Saboteur: Imperceptible Adversarial Attacks against Black-Box Retrieval-Augmented Generation Systems | S1; sec: S2 | O1 | T1 | Findings of ACL | Paper Code |
| 2025 | One Shot Dominance: Knowledge Poisoning Attack on Retrieval-Augmented Generation Systems (AuthChain) | S1; sec: S2 | O1 | T1 | Findings of EMNLP | Paper Code |
| 2025 | The RAG Paradox: A Black-Box Attack Exploiting Unintentional Vulnerabilities in Retrieval-Augmented Generation Systems | S1; sec: S2 | O1 | T1 | Findings of EMNLP | Paper |
| 2025 | PoisonedRAG: Knowledge Corruption Attacks to Retrieval-Augmented Generation of Large Language Models | S1; sec: S2 | O1 | T1 | USENIX Security | Paper Code |
| 2024 | Typos that Broke the RAG's Back: Genetic Attack on RAG Pipeline by Simulating Documents in the Wild via Low-Level Perturbations (GARAG) | S1; sec: S2 | O1 | T1 | Findings of EMNLP | Paper |
| 2024 | Human-Imperceptible Retrieval Poisoning Attacks in LLM-Powered Applications | S1; sec: S3 | O1 | T1 | FSE Companion | Paper |
| 2024 | HijackRAG: Hijacking Attacks against Retrieval-Augmented Large Language Models | S1; sec: S2, S3 | O1 | T1 | arXiv | Paper Code |