RAG-Pull uses minimal invisible UTF perturbations on queries or target code to achieve near-perfect redirection of RAG retrieval to malicious snippets that enable remote code execution and SQL injection.
- How it works step-by-step
1 Pith paper cite this work. Polarity classification is still indexing.
1
Pith paper citing it
fields
cs.CR 1years
2025 1verdicts
UNVERDICTED 1representative citing papers
citing papers explorer
-
RAG-Pull: Turning Retrieval into a Code-Injection Channel via Invisible Unicode Perturbations
RAG-Pull uses minimal invisible UTF perturbations on queries or target code to achieve near-perfect redirection of RAG retrieval to malicious snippets that enable remote code execution and SQL injection.