Pith. sign in

Paper Citation Record · LEDGER

PoisonedRAG: Knowledge Corruption Attacks to Retrieval-Augmented Generation of Large Language Models

As of 19 August 2026, this Paper Citation Record lists 0 of 0 outbound references and 86 inbound Pith citation observations for arXiv:2402.07867.

A citation records a reference. It does not transfer a finding from one paper to another.

pith.paper-citation-record.v1
2402.07867 v3

Coverage vector

measured 0 of 0 reference resolution

Typed states for the displayed outbound observations.

Source: paper_references, paper_reference_links

measured 86 of 86 standing notices

One-hop event checks from named stored sources.

Source: scholarly_work_events, retraction_status_cache, observed 2026-08-19T06:32:44.657259+00:00

measured 86 of 86 inbound itemization

Pith citing papers itemized under the disclosed page cap.

Source: paper_references, paper_reference_links, observed 2026-08-16T12:19:16.802570Z

measured 1 of 1 external citation measurements

A source-named dated measurement, never combined with another source.

Source: arxiv_reference, observed 2026-08-05T02:28:24.338817Z

Reference resolution

0 of 0 outbound references displayed

  • verified exact0
  • verified fuzzy0
  • unresolved0
  • parse uncertain0
  • malformed identifier0
  • metadata mismatch0

External citation measurements

11
arxiv_reference, observed 2026-08-05T02:28:24.338817Z

Outbound references

No outbound reference observations are available for this paper version.

Pith citing papers

Observation ddc5813a-0da8-494c-adcf-dcd084547565 · inbound

Trustworthiness in Retrieval-Augmented Generation Systems: A Survey cites this paper.

Trustworthiness in Retrieval-Augmented Generation Systems: A Survey PoisonedRAG: Knowledge Corruption Attacks to Retrieval-Augmented Generation of Large Language Models

Reference 79

Resolution
verified exact
arxiv_id, observed 2026-05-23T21:08:25.779893Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=pdf_text observed=2026-05-23T21:08:11.787013Z digest=sha256:29812e619d75bdc23871c591238a8f6b3c137228cbabf4b33f263e3daa28b3ef

Observation 70944d01-9635-4dee-bbca-acf15024df61 · inbound

Agent Security Bench (ASB): Formalizing and Benchmarking Attacks and Defenses in LLM-based Agents cites this paper.

Agent Security Bench (ASB): Formalizing and Benchmarking Attacks and Defenses in LLM-based Agents PoisonedRAG: Knowledge Corruption Attacks to Retrieval-Augmented Generation of Large Language Models

Reference 165

Resolution
verified exact
arxiv_id, observed 2026-05-12T13:36:57.079379Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=arxiv_source observed=2026-05-12T13:36:57.011451Z digest=sha256:894136b89699e04e813ea53e1461cee8966feb85f92564a02eadea570fd4303d

Observation 307d9157-6827-46a3-9610-336acdc3a7a5 · inbound

The Dark Side of Trust: Authority Citation-Driven Jailbreak Attacks on Large Language Models cites this paper.

The Dark Side of Trust: Authority Citation-Driven Jailbreak Attacks on Large Language Models PoisonedRAG: Knowledge Corruption Attacks to Retrieval-Augmented Generation of Large Language Models

Reference 63

Resolution
unresolved
no resolver link, observed 2026-08-12T18:38:43.961438Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-12T18:38:43.961438Z digest=sha256:47897f2e2b9e8adea3fb35d0e543873b338a7817195d1c751c5a0324a3a63d31

Observation 221bd099-962e-4ceb-abdc-b0dc605dd0a0 · inbound

RevPRAG: Revealing Poisoning Attacks in Retrieval-Augmented Generation through LLM Activation Analysis cites this paper.

RevPRAG: Revealing Poisoning Attacks in Retrieval-Augmented Generation through LLM Activation Analysis PoisonedRAG: Knowledge Corruption Attacks to Retrieval-Augmented Generation of Large Language Models

Reference 46

Resolution
unresolved
no resolver link, observed 2026-08-12T10:47:45.879873Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-12T10:47:45.879873Z digest=sha256:b8889b104aae6d8e0add9d45dbff048733560e14c46518115816843e85059255

Observation 9d890f49-ea25-47dc-a194-15dab11e8c61 · inbound

From Allies to Adversaries: Manipulating LLM Tool-Calling through Adversarial Injection cites this paper.

From Allies to Adversaries: Manipulating LLM Tool-Calling through Adversarial Injection PoisonedRAG: Knowledge Corruption Attacks to Retrieval-Augmented Generation of Large Language Models

Reference 31

Resolution
unresolved
no resolver link, observed 2026-08-11T16:17:43.494389Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-11T16:17:43.494389Z digest=sha256:8f1e27f4dde70264998668314eb0304cb583e32e4645144c8686a521a1644d9f

Observation caa1e885-fbf4-4577-9274-2b7c1b1bba02 · inbound

Adversarial Hubness in Multi-Modal Retrieval cites this paper.

Adversarial Hubness in Multi-Modal Retrieval PoisonedRAG: Knowledge Corruption Attacks to Retrieval-Augmented Generation of Large Language Models

Reference 94

Resolution
verified exact
arxiv_id, observed 2026-05-23T06:42:39.708087Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=pdf_text observed=2026-05-23T06:39:36.039613Z digest=sha256:9a47f2f6521e1f18ba75198127a8d8dde845162e660d4f28df3b911bdf55e98c

Observation 60b84998-89ef-44e9-97d6-49703b058052 · inbound

Towards More Robust Retrieval-Augmented Generation: Evaluating RAG Under Adversarial Poisoning Attacks cites this paper.

Towards More Robust Retrieval-Augmented Generation: Evaluating RAG Under Adversarial Poisoning Attacks PoisonedRAG: Knowledge Corruption Attacks to Retrieval-Augmented Generation of Large Language Models

Reference 35

Resolution
unresolved
no resolver link, observed 2026-08-11T10:24:21.794378Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-11T10:24:21.794378Z digest=sha256:0f7d181654d279105a49b765f054194bff698ec23576baea0ceaff61fb51448a

Observation 6e0924ce-5a38-449b-b381-e8fec67474d0 · inbound

RAG-WM: An Efficient Black-Box Watermarking Approach for Retrieval-Augmented Generation of Large Language Models cites this paper.

RAG-WM: An Efficient Black-Box Watermarking Approach for Retrieval-Augmented Generation of Large Language Models PoisonedRAG: Knowledge Corruption Attacks to Retrieval-Augmented Generation of Large Language Models

Reference 74

Resolution
unresolved
no resolver link, observed 2026-08-10T21:18:38.328637Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-10T21:18:38.328637Z digest=sha256:ef27af1b073f5a23d54e93eabb44090245666d0755190f33f8d0ab25c6c2c249

Observation c0311032-7160-4434-b041-f833f24feec4 · inbound

Poison-RAG: Adversarial Data Poisoning Attacks on Retrieval-Augmented Generation in Recommender Systems cites this paper.

Poison-RAG: Adversarial Data Poisoning Attacks on Retrieval-Augmented Generation in Recommender Systems PoisonedRAG: Knowledge Corruption Attacks to Retrieval-Augmented Generation of Large Language Models

Reference 16

Resolution
unresolved
no resolver link, observed 2026-08-10T17:59:56.251789Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-10T17:59:56.251789Z digest=sha256:20f98e7e6df9e63cbb06e02dc4d01f245eb68f1170e157124d22975ab4fc63a5

Observation baf3476a-012d-4514-ad7c-204431ccaa9f · inbound

RbFT: Robust Fine-tuning for Retrieval-Augmented Generation against Retrieval Defects cites this paper.

RbFT: Robust Fine-tuning for Retrieval-Augmented Generation against Retrieval Defects PoisonedRAG: Knowledge Corruption Attacks to Retrieval-Augmented Generation of Large Language Models

Reference 61

Resolution
unresolved
no resolver link, observed 2026-08-09T23:48:54.096885Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-09T23:48:54.096885Z digest=sha256:e640edefc9cc77c4efe6f4c9cf530d7ec19f4ef13271a0c737452cabf2331685

Observation c9607b22-6116-4922-8fa9-84e07cc7e43e · inbound

Exploring the Security Threats of Knowledge Base Poisoning in Retrieval-Augmented Code Generation cites this paper.

Exploring the Security Threats of Knowledge Base Poisoning in Retrieval-Augmented Code Generation PoisonedRAG: Knowledge Corruption Attacks to Retrieval-Augmented Generation of Large Language Models

Reference 92

Resolution
unresolved
no resolver link, observed 2026-08-09T05:31:14.492097Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-09T05:31:14.492097Z digest=sha256:64b8e005fad30e4e21f5c222a9b8f96e3c3cf8091da0aaf3a59b3dc071bad266

Observation c4987acd-3e48-4441-91f7-83a942ae0d80 · inbound

Unsafe LLM-Based Search: Quantitative Analysis and Mitigation of Safety Risks in AI Web Search cites this paper.

Unsafe LLM-Based Search: Quantitative Analysis and Mitigation of Safety Risks in AI Web Search PoisonedRAG: Knowledge Corruption Attacks to Retrieval-Augmented Generation of Large Language Models

Reference 78

Resolution
unresolved
no resolver link, observed 2026-08-08T20:57:43.624290Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-08T20:57:43.624290Z digest=sha256:b6cca34fce6290756554005e12c1ea7eb46091ef7acbbe40a7f5114e3011bf54

Observation 27efaa9a-50aa-4e30-87aa-399eeb3fc73b · inbound

MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents cites this paper.

MELON: Provable Defense Against Indirect Prompt Injection Attacks in AI Agents PoisonedRAG: Knowledge Corruption Attacks to Retrieval-Augmented Generation of Large Language Models

Reference 39

Resolution
unresolved
no resolver link, observed 2026-08-08T20:06:58.396831Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-08T20:06:58.396831Z digest=sha256:941384a78824b161d0e6ef56d110930d507f4d01c3075a88f8b23b8e207c3445

Observation 87ed32e5-a9b7-46c9-98ce-e5a0120a97fa · inbound

A Survey on Backdoor Threats in Large Language Models (LLMs): Attacks, Defenses, and Evaluations cites this paper.

A Survey on Backdoor Threats in Large Language Models (LLMs): Attacks, Defenses, and Evaluations PoisonedRAG: Knowledge Corruption Attacks to Retrieval-Augmented Generation of Large Language Models

Reference 122

Resolution
unresolved
no resolver link, observed 2026-08-09T00:50:00.452963Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-09T00:50:00.452963Z digest=sha256:b7bd06b989ee7f1fa15018a32313b37ab239235575b6920e008705585ba7afb0

Observation 8609c883-dc30-4836-bfb4-6a128e862741 · inbound

Towards Trustworthy Retrieval Augmented Generation for Large Language Models: A Survey cites this paper.

Towards Trustworthy Retrieval Augmented Generation for Large Language Models: A Survey PoisonedRAG: Knowledge Corruption Attacks to Retrieval-Augmented Generation of Large Language Models

Reference 247

Resolution
unresolved
no resolver link, observed 2026-08-08T19:15:25.791670Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-08T19:15:25.791670Z digest=sha256:b47b584ad6e598546992470d5ae1c8faf7e49ac671ae9999dba62ba871a8a0ae

Observation 1ecb82a5-4cff-488a-a1f6-0533808dbdbf · inbound

ParetoRAG: Leveraging Sentence-Context Attention for Robust and Efficient Retrieval-Augmented Generation cites this paper.

ParetoRAG: Leveraging Sentence-Context Attention for Robust and Efficient Retrieval-Augmented Generation PoisonedRAG: Knowledge Corruption Attacks to Retrieval-Augmented Generation of Large Language Models

Reference 51

Resolution
unresolved
no resolver link, observed 2026-08-08T10:11:13.404652Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-08T10:11:13.404652Z digest=sha256:313b70c8fd2009b6b4d775f113a853b346198536643b1e7493c36d47ea91f163

Observation e82cbe66-f7fa-4f7e-89ff-287c47565931 · inbound

Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks cites this paper.

Commercial LLM Agents Are Already Vulnerable to Simple Yet Dangerous Attacks PoisonedRAG: Knowledge Corruption Attacks to Retrieval-Augmented Generation of Large Language Models

Reference 27

Resolution
unresolved
no resolver link, observed 2026-08-08T04:37:28.867597Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-08T04:37:28.867597Z digest=sha256:78f191e92dd7f3338ff9cae1a7685cbe7f5bb7149a1d2e38ce4b94861368f4b9

Observation c28bd23f-fa59-4346-8281-407b14a69e37 · inbound

Retrieval-Augmented Generation with Conflicting Evidence cites this paper.

Retrieval-Augmented Generation with Conflicting Evidence PoisonedRAG: Knowledge Corruption Attacks to Retrieval-Augmented Generation of Large Language Models

Reference 52

Resolution
unresolved
no resolver link, observed 2026-08-16T12:19:16.802570Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-16T12:19:16.802570Z digest=sha256:eef612005ba3b7f4b4bc0cbee80c6cb8e3a5bda282e8a4e887aa5bdd76721876

Observation 01b79e01-c451-442b-931a-7c8e0cabfc80 · inbound

Retrieval Augmented Generation Evaluation in the Era of Large Language Models: A Comprehensive Survey cites this paper.

Retrieval Augmented Generation Evaluation in the Era of Large Language Models: A Comprehensive Survey PoisonedRAG: Knowledge Corruption Attacks to Retrieval-Augmented Generation of Large Language Models

Reference 86

Resolution
unresolved
no resolver link, observed 2026-08-16T11:40:41.764393Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-16T11:40:41.764393Z digest=sha256:1a8c312640e0e02717c236167d1bb12be4e81a4698502e4df5659cee1cdcc318

Observation d8e7ef2a-26a8-4040-944c-9bdb642032b1 · inbound

Prompt Injection Attack to Tool Selection in LLM Agents cites this paper.

Prompt Injection Attack to Tool Selection in LLM Agents PoisonedRAG: Knowledge Corruption Attacks to Retrieval-Augmented Generation of Large Language Models

Reference 21

Resolution
verified exact
arxiv_id, observed 2026-05-16T17:08:28.970499Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=pdf_text observed=2026-05-16T17:08:28.933831Z digest=sha256:303f64aaecf99adaa0304bc6a1e7451d0814be73ac76f7d4c28a871efe66e260

Observation 915c5096-d3a4-47d5-ae34-b4928a7e3fd3 · inbound

Chain-of-Defensive-Thought: Structured Reasoning Elicits Robustness in Large Language Models against Reference Corruption cites this paper.

Chain-of-Defensive-Thought: Structured Reasoning Elicits Robustness in Large Language Models against Reference Corruption PoisonedRAG: Knowledge Corruption Attacks to Retrieval-Augmented Generation of Large Language Models

Reference 30

Resolution
unresolved
no resolver link, observed 2026-08-16T05:25:30.361882Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-16T05:25:30.361882Z digest=sha256:9b7f1a7a2800c82a40d0383923ebfb97f92b170609df58328000220be40ff831

Observation 571fb5d4-1a82-495d-8528-4f62d9015c0d · inbound

Hoist with His Own Petard: Inducing Guardrails to Facilitate Denial-of-Service Attacks on Retrieval-Augmented Generation of LLMs cites this paper.

Hoist with His Own Petard: Inducing Guardrails to Facilitate Denial-of-Service Attacks on Retrieval-Augmented Generation of LLMs PoisonedRAG: Knowledge Corruption Attacks to Retrieval-Augmented Generation of Large Language Models

Reference 27

Resolution
unresolved
no resolver link, observed 2026-08-16T05:01:32.089713Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-16T05:01:32.089713Z digest=sha256:a52b5d4776911872a2366fbd806882fdd14995866becbb78b6f7a27b91769c56

Observation b15c7f28-be0b-45ac-b0bb-499b8c0e8a2c · inbound

Stealthy LLM-Driven Data Poisoning Attacks Against Embedding-Based Retrieval-Augmented Recommender Systems cites this paper.

Stealthy LLM-Driven Data Poisoning Attacks Against Embedding-Based Retrieval-Augmented Recommender Systems PoisonedRAG: Knowledge Corruption Attacks to Retrieval-Augmented Generation of Large Language Models

Reference 13

Resolution
unresolved
no resolver link, observed 2026-08-15T23:12:44.422459Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-15T23:12:44.422459Z digest=sha256:df6ee67b02756db6ef0bc4e5444d06c6c9f6bff6474b5525c287c1d8c38c9284

Observation 40b93cdc-ef77-45d0-a5d3-b962a1a3f327 · inbound

POISONCRAFT: Practical Poisoning of Retrieval-Augmented Generation for Large Language Models cites this paper.

POISONCRAFT: Practical Poisoning of Retrieval-Augmented Generation for Large Language Models PoisonedRAG: Knowledge Corruption Attacks to Retrieval-Augmented Generation of Large Language Models

Reference 20

Resolution
unresolved
no resolver link, observed 2026-08-15T22:43:05.985747Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-15T22:43:05.985747Z digest=sha256:aaa51c0d085a9b4c0901936e83c43c7670ce186d3636b13906720b2b820a7d91

Observation 7cb77f61-c462-4476-9136-0a36035ece07 · inbound

One Shot Dominance: Knowledge Poisoning Attack on Retrieval-Augmented Generation Systems cites this paper.

One Shot Dominance: Knowledge Poisoning Attack on Retrieval-Augmented Generation Systems PoisonedRAG: Knowledge Corruption Attacks to Retrieval-Augmented Generation of Large Language Models

Reference 9

Resolution
metadata mismatch
arxiv_id, observed 2026-05-22T15:21:44.826695Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=pdf_text observed=2026-05-22T15:19:08.867224Z digest=sha256:7db1c886ff3b67aca71ae3b895d65ce53c021e03f9dbc7f5b7ea6fa8fa2f2e27

Observation 6eae61db-a30a-4373-8ec5-4e8cff431d01 · inbound

A Survey of Attacks on Large Language Models cites this paper.

A Survey of Attacks on Large Language Models PoisonedRAG: Knowledge Corruption Attacks to Retrieval-Augmented Generation of Large Language Models

Reference 17

Resolution
unresolved
no resolver link, observed 2026-08-15T20:34:34.286851Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-15T20:34:34.286851Z digest=sha256:8291d2690cd51107f5d306a16f69c6bc016b4a36ad50ceac0f96ab4d8b2a4377

Observation eb6d17ad-ae79-4242-b13d-9f30605cdb0d · inbound

Web Intellectual Property at Risk: Preventing Unauthorized Real-Time Retrieval by Large Language Models cites this paper.

Web Intellectual Property at Risk: Preventing Unauthorized Real-Time Retrieval by Large Language Models PoisonedRAG: Knowledge Corruption Attacks to Retrieval-Augmented Generation of Large Language Models

Reference 45

Resolution
unresolved
no resolver link, observed 2026-08-15T20:34:34.405907Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-15T20:34:34.405907Z digest=sha256:eae11d95f6ed091eb8a81e964426c4190d9ddbcace5b8d13e3bba39cb7de9053

Observation 70d25c1e-5534-4f15-9d09-1d0918f1999d · inbound

Safety Degradation in AI Agents cites this paper.

Safety Degradation in AI Agents PoisonedRAG: Knowledge Corruption Attacks to Retrieval-Augmented Generation of Large Language Models

Reference 27

Resolution
unresolved
no resolver link, observed 2026-08-07T15:41:04.546839Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T15:41:04.546839Z digest=sha256:a686e41dec4dbbb3aa8e0faa5b55dd85b71c670be84da69a6dc08889a40e8193

Observation 26e778b4-da45-4896-8dfd-0f438f6e2eee · inbound

Scalable Defense against In-the-wild Jailbreaking Attacks with Safety Context Retrieval cites this paper.

Scalable Defense against In-the-wild Jailbreaking Attacks with Safety Context Retrieval PoisonedRAG: Knowledge Corruption Attacks to Retrieval-Augmented Generation of Large Language Models

Reference 58

Resolution
unresolved
no resolver link, observed 2026-08-07T15:15:48.828674Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T15:15:48.828674Z digest=sha256:0a6f10966a4bfa230d8885683af5b89fd15c4c7866cbb9f04a3de4a28ae8be19

Observation f1b3446c-fa44-43ca-8929-8b1581af798e · inbound

Ranking Free RAG: Replacing Re-ranking with Selection in RAG for Sensitive Domains cites this paper.

Ranking Free RAG: Replacing Re-ranking with Selection in RAG for Sensitive Domains PoisonedRAG: Knowledge Corruption Attacks to Retrieval-Augmented Generation of Large Language Models

Reference 6

Resolution
unresolved
no resolver link, observed 2026-08-07T15:14:45.122719Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-07T15:14:45.122719Z digest=sha256:0c4d232963325e9c1629a977c4d04977909a1465c7a034b4bbc6e748ae149859

Observation 3429a0c7-ebfc-42f1-a537-070773e75f4b · inbound

Chain-of-Thought Poisoning Attacks against R1-based Retrieval-Augmented Generation Systems cites this paper.

Chain-of-Thought Poisoning Attacks against R1-based Retrieval-Augmented Generation Systems PoisonedRAG: Knowledge Corruption Attacks to Retrieval-Augmented Generation of Large Language Models

Reference 33

Resolution
unresolved
no resolver link, observed 2026-08-07T15:06:01.723487Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T15:06:01.723487Z digest=sha256:556f7d81da358b7dc788fb61cc430e363e03680fd8dd5cc03c771d4482a1347b

Observation 63b0bf57-701b-43b9-9cd2-c6965c5b5d85 · inbound

The Silent Saboteur: Imperceptible Adversarial Attacks against Black-Box Retrieval-Augmented Generation Systems cites this paper.

The Silent Saboteur: Imperceptible Adversarial Attacks against Black-Box Retrieval-Augmented Generation Systems PoisonedRAG: Knowledge Corruption Attacks to Retrieval-Augmented Generation of Large Language Models

Reference 49

Resolution
unresolved
no resolver link, observed 2026-08-07T14:36:35.536497Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-07T14:36:35.536497Z digest=sha256:04334ae06602790f41b23f850253075e070247cdb209db61f7768b133fbcae82

Observation d4e3c587-9f9b-4d6e-bff5-ea614be67383 · inbound

Evaluating the Retrieval Robustness of Large Language Models cites this paper.

Evaluating the Retrieval Robustness of Large Language Models PoisonedRAG: Knowledge Corruption Attacks to Retrieval-Augmented Generation of Large Language Models

Reference 44

Resolution
unresolved
no resolver link, observed 2026-08-07T13:25:07.369937Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-07T13:25:07.369937Z digest=sha256:a25efdd0a40568c005bd83c3a82e33caeba52160c3a75941915eaafcf65ba201

Observation fbf74ff2-eacd-4e67-a4e0-ef15b2f5fb08 · inbound

Spa-VLM: Stealthy Poisoning Attacks on RAG-based VLM cites this paper.

Spa-VLM: Stealthy Poisoning Attacks on RAG-based VLM PoisonedRAG: Knowledge Corruption Attacks to Retrieval-Augmented Generation of Large Language Models

Reference 10

Resolution
unresolved
no resolver link, observed 2026-08-07T13:21:40.020790Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T13:21:40.020790Z digest=sha256:fe6e4b615eebaa3dfa4011a608f28a9f6631d0b02cbe666a787e57de16233a15

Observation da296a31-3aac-42c9-871e-9b8d6bd2d6ff · inbound

Across Programming Language Silos: A Study on Cross-Lingual Retrieval-augmented Code Generation cites this paper.

Across Programming Language Silos: A Study on Cross-Lingual Retrieval-augmented Code Generation PoisonedRAG: Knowledge Corruption Attacks to Retrieval-Augmented Generation of Large Language Models

Reference 34

Resolution
verified exact
arxiv_id, observed 2026-05-19T11:53:03.497378Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=pdf_text observed=2026-05-19T11:52:44.990234Z digest=sha256:ef4f6f5445761843d7331235a4841ac54f3f61e2d3f5f6b373a3b6eb0b05f527

Observation 613a9767-052a-4197-a428-1d31d0f2dc35 · inbound

PRJ: Perception-Retrieval-Judgement for Generated Images cites this paper.

PRJ: Perception-Retrieval-Judgement for Generated Images PoisonedRAG: Knowledge Corruption Attacks to Retrieval-Augmented Generation of Large Language Models

Reference 41

Resolution
unresolved
no resolver link, observed 2026-08-07T11:02:05.546108Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T11:02:05.546108Z digest=sha256:f781f83e8f060a64de19b5edb01fa3ed5fc0ac75eccf838a53cdca461f8e3f55

Observation 6c8a045d-7ffa-4294-87f2-4edcf4373957 · inbound

Through the Stealth Lens: Attention-Aware Defenses Against Poisoning in RAG cites this paper.

Through the Stealth Lens: Attention-Aware Defenses Against Poisoning in RAG PoisonedRAG: Knowledge Corruption Attacks to Retrieval-Augmented Generation of Large Language Models

Reference 18

Resolution
verified exact
arxiv_id, observed 2026-05-25T08:15:34.142810Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=pdf_text observed=2026-05-25T08:10:31.473565Z digest=sha256:93d021815ec090144ae07464443c03bfcae6c0ef57fb194e8dab8f2cd20de757

Observation c8111ef8-2935-4542-afef-9c37f54c55f8 · inbound

Bias Amplification in RAG: Poisoning Knowledge Retrieval to Steer LLMs cites this paper.

Bias Amplification in RAG: Poisoning Knowledge Retrieval to Steer LLMs PoisonedRAG: Knowledge Corruption Attacks to Retrieval-Augmented Generation of Large Language Models

Reference 31

Resolution
unresolved
no resolver link, observed 2026-08-07T04:15:38.906102Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T04:15:38.906102Z digest=sha256:9b1bd9186f8c4427a64a49719f0e210e4e6b088c55a199c6710d06b289069aa7

Observation 3e6a1912-492f-467e-a89c-202ac72dca6b · inbound

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems cites this paper.

We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems PoisonedRAG: Knowledge Corruption Attacks to Retrieval-Augmented Generation of Large Language Models

Reference 108

Resolution
unresolved
no resolver link, observed 2026-08-07T00:32:36.778570Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:32:36.778570Z digest=sha256:140988866f83de020d55585ce11c9975d3d83fd82d0a0a49945fc637519095fa

Observation d6cda81d-3e8a-46fd-8dbd-f9cec06df78c · inbound

CrEst: Credibility Estimation for Contexts in LLMs via Weak Supervision cites this paper.

CrEst: Credibility Estimation for Contexts in LLMs via Weak Supervision PoisonedRAG: Knowledge Corruption Attacks to Retrieval-Augmented Generation of Large Language Models

Reference 37

Resolution
unresolved
no resolver link, observed 2026-08-07T00:15:26.452348Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-07T00:15:26.452348Z digest=sha256:f86493945a071f56332d4083ff544798c2174ca9341c95a2787516564dab7ede

Observation 5994bb5f-3587-4829-8733-12ba263c704b · inbound

The Hidden Threat in Plain Text: Attacking RAG Data Loaders cites this paper.

The Hidden Threat in Plain Text: Attacking RAG Data Loaders PoisonedRAG: Knowledge Corruption Attacks to Retrieval-Augmented Generation of Large Language Models

Reference 28

Resolution
unresolved
no resolver link, observed 2026-08-06T19:37:31.621811Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T19:37:31.621811Z digest=sha256:38b93771d2e93f3882a5dcaf936138e61f5ef8d4802526d0bf04d08462abbfd5

Observation 3d9a0327-a6ad-4b9f-8a4f-e66d02300fdb · inbound

RAG Safety: Exploring Knowledge Poisoning Attacks to Retrieval-Augmented Generation cites this paper.

RAG Safety: Exploring Knowledge Poisoning Attacks to Retrieval-Augmented Generation PoisonedRAG: Knowledge Corruption Attacks to Retrieval-Augmented Generation of Large Language Models

Reference 18

Resolution
unresolved
no resolver link, observed 2026-08-06T19:01:14.484478Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-06T19:01:14.484478Z digest=sha256:1258c24f9877c54951ffac607bed3286c14b34c6c0696f08317c51c0e038b302

Observation 68edff08-d516-4b51-998d-c33ea54feda0 · inbound

Safeguarding RAG Pipelines with GMTP: A Gradient-based Masked Token Probability Method for Poisoned Document Detection cites this paper.

Safeguarding RAG Pipelines with GMTP: A Gradient-based Masked Token Probability Method for Poisoned Document Detection PoisonedRAG: Knowledge Corruption Attacks to Retrieval-Augmented Generation of Large Language Models

Reference 49

Resolution
unresolved
no resolver link, observed 2026-08-06T14:42:08.223022Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-06T14:42:08.223022Z digest=sha256:0b763b55b7d4123bb5c71c6ff83ecf32da1fb3b8a81a6a2cff91d69316dc753e

Observation 104865e9-671a-4f27-a3c9-35bb198575ca · inbound

Quantifying Conversation Drift in MCP via Latent Polytope cites this paper.

Quantifying Conversation Drift in MCP via Latent Polytope PoisonedRAG: Knowledge Corruption Attacks to Retrieval-Augmented Generation of Large Language Models

Reference 31

Resolution
unresolved
no resolver link, observed 2026-08-05T22:51:28.198095Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-05T22:51:28.198095Z digest=sha256:1c77895493303a8b7a68be1b2e54eba2c8219c11821cd256cbc3bb8d926c412f

Observation db791a78-d474-447c-b765-2951a9e0f8be · inbound

Layer-Wise Perturbations via Sparse Autoencoders for Adversarial Text Generation cites this paper.

Layer-Wise Perturbations via Sparse Autoencoders for Adversarial Text Generation PoisonedRAG: Knowledge Corruption Attacks to Retrieval-Augmented Generation of Large Language Models

Reference 161

Resolution
unresolved
no resolver link, observed 2026-08-05T20:31:47.455320Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T20:31:47.455320Z digest=sha256:b719f34785b359706c342a4b48fa325a2da20211ed594cd3b7dccdac768ee8a5

Observation 1a0c9a77-6560-4646-af5b-272626ed5d7a · inbound

Lexical Hints of Accuracy in LLM Reasoning Chains cites this paper.

Lexical Hints of Accuracy in LLM Reasoning Chains PoisonedRAG: Knowledge Corruption Attacks to Retrieval-Augmented Generation of Large Language Models

Reference 18

Resolution
unresolved
no resolver link, observed 2026-08-05T18:48:53.146867Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-05T18:48:53.146867Z digest=sha256:67393a38e38217a2061f84359f7d07a92dbcf3ca09c3ff84c85bb145ea1e359a

Observation f88b039d-eff5-474b-87e4-a7f89178a7c6 · inbound

ImportSnare: Directed "Code Manual" Hijacking in Retrieval-Augmented Code Generation cites this paper.

ImportSnare: Directed "Code Manual" Hijacking in Retrieval-Augmented Code Generation PoisonedRAG: Knowledge Corruption Attacks to Retrieval-Augmented Generation of Large Language Models

Reference 60

Resolution
unresolved
no resolver link, observed 2026-08-04T21:34:00.816332Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-04T21:34:00.816332Z digest=sha256:2befbc7bd3d5de7422e726552278eacd0ce9dc05550b808aa31cf67a5be21b44

Observation 0a0fe999-d014-48ed-828f-0fb6d4974e68 · inbound

ADMIT: Few-shot Knowledge Poisoning Attacks on RAG-based Fact Checking cites this paper.

ADMIT: Few-shot Knowledge Poisoning Attacks on RAG-based Fact Checking PoisonedRAG: Knowledge Corruption Attacks to Retrieval-Augmented Generation of Large Language Models

Reference 6

Resolution
metadata mismatch
arxiv_id, observed 2026-05-21T20:04:20.244047Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=pdf_text observed=2026-05-21T20:03:37.620559Z digest=sha256:60e80173481b9f355db1172b507d75fa6a7e0ddc30c1788ace4381b29ad737bb

Observation e6d9ca32-0456-469f-9b3f-c159b2774f34 · inbound

Position: LLM Watermarking Should Align Stakeholders' Incentives for Practical Adoption cites this paper.

Position: LLM Watermarking Should Align Stakeholders' Incentives for Practical Adoption PoisonedRAG: Knowledge Corruption Attacks to Retrieval-Augmented Generation of Large Language Models

Reference 70

Resolution
verified exact
arxiv_id, observed 2026-05-18T05:25:54.521932Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=pdf_text observed=2026-05-18T05:24:25.622071Z digest=sha256:557bcf732de2c592e27ee723fc082507b91a6a1b9204fe1b54d55c82789e91cf

Observation 4d007f45-fa61-4d2e-8318-4681601e2899 · inbound

Agentic AI Security: Threats, Defenses, Evaluation, and Open Challenges cites this paper.

Agentic AI Security: Threats, Defenses, Evaluation, and Open Challenges PoisonedRAG: Knowledge Corruption Attacks to Retrieval-Augmented Generation of Large Language Models

Reference 117

Resolution
verified exact
arxiv_id, observed 2026-05-18T03:42:22.361207Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=pdf_text observed=2026-05-18T03:42:10.703369Z digest=sha256:9ea01ddb5cad0e14b9f3f1182eb29960f2e61fb62b3d71d84cfa1d3880a8b9db

Observation 8446b069-6eac-4c5f-a985-b53f8ef5e059 · inbound

Epistemic Bias Injection: Manipulating LLM Opinion via Selective Context Retrieval cites this paper.

Epistemic Bias Injection: Manipulating LLM Opinion via Selective Context Retrieval PoisonedRAG: Knowledge Corruption Attacks to Retrieval-Augmented Generation of Large Language Models

Reference 10

Resolution
unresolved
no resolver link, observed 2026-08-03T19:27:04.053807Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-03T19:27:04.053807Z digest=sha256:d21bc04c35b64d3334c94ee10f9fd29386c04b491a1fc21af082522b89f7a086

Observation c0172594-d89a-4d57-8fd3-11adc1815b4f · inbound

Your Agent, Their Asset: A Real-World Safety Analysis of OpenClaw cites this paper.

Your Agent, Their Asset: A Real-World Safety Analysis of OpenClaw PoisonedRAG: Knowledge Corruption Attacks to Retrieval-Augmented Generation of Large Language Models

Reference 22

Resolution
verified exact
arxiv_id, observed 2026-05-10T23:05:49.040793Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=pdf_text observed=2026-05-10T19:20:52.845052Z digest=sha256:4d728dc5aef0c38d752d8aa473ff60aeff91dc505423898d4bd244f77158b5db

Observation a5099c56-c40c-42b2-b2d2-c3a5d2ec096b · inbound

RefineRAG: Word-Level Poisoning Attacks via Retriever-Guided Text Refinement cites this paper.

RefineRAG: Word-Level Poisoning Attacks via Retriever-Guided Text Refinement PoisonedRAG: Knowledge Corruption Attacks to Retrieval-Augmented Generation of Large Language Models

Reference 31

Resolution
verified exact
arxiv_id, observed 2026-05-11T05:16:04.908987Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=pdf_text observed=2026-05-10T18:13:22.221234Z digest=sha256:04b401e8d1846a44e208d7f17234f7711a5391130c2809c28a2ba9c08c42936c

Observation ba9b10a6-d152-4c5f-ab45-af4a4b2c6991 · inbound

AdversarialCoT: Single-Document Retrieval Poisoning for LLM Reasoning cites this paper.

AdversarialCoT: Single-Document Retrieval Poisoning for LLM Reasoning PoisonedRAG: Knowledge Corruption Attacks to Retrieval-Augmented Generation of Large Language Models

Reference 43

Resolution
verified exact
arxiv_id, observed 2026-05-11T08:56:03.767307Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=pdf_text observed=2026-05-10T16:22:49.133595Z digest=sha256:53f05e6a5001d86a5aab9251b4159e570e8db028bd15127ce79d9d4cd9c90743

Observation 872db6f1-9613-4506-b8e4-0444c3ec1990 · inbound

A Systematic Survey of Security Threats and Defenses in LLM-Based AI Agents: A Layered Attack Surface Framework cites this paper.

A Systematic Survey of Security Threats and Defenses in LLM-Based AI Agents: A Layered Attack Surface Framework PoisonedRAG: Knowledge Corruption Attacks to Retrieval-Augmented Generation of Large Language Models

Reference 39

Resolution
verified exact
arxiv_id, observed 2026-05-11T20:51:09.531127Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=pdf_text observed=2026-05-08T07:53:13.746141Z digest=sha256:6a05a7c2f8a2d9ef77318ea10d1cea854a8785faeb5cb7a6734612dd45e514fc

Observation cc35d871-ca83-4dbc-9632-b3ac497a6ead · inbound

When Child Inherits: Modeling and Exploiting Subagent Spawn in Multi-Agent Networks cites this paper.

When Child Inherits: Modeling and Exploiting Subagent Spawn in Multi-Agent Networks PoisonedRAG: Knowledge Corruption Attacks to Retrieval-Augmented Generation of Large Language Models

Reference 14

Resolution
verified exact
arxiv_id, observed 2026-05-12T08:01:33.103211Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=pdf_text observed=2026-05-12T01:20:55.221345Z digest=sha256:164f203fcefa7275268ac60235766accdb20197a1b5ea1219ca9db200f2c8651

Observation 5c7c5f58-6b48-4e5d-b575-e713f6e66076 · inbound

Oracle Poisoning: Corrupting Knowledge Graphs to Weaponise AI Agent Reasoning cites this paper.

Oracle Poisoning: Corrupting Knowledge Graphs to Weaponise AI Agent Reasoning PoisonedRAG: Knowledge Corruption Attacks to Retrieval-Augmented Generation of Large Language Models

Reference 38

Resolution
verified exact
arxiv_id, observed 2026-05-12T07:37:03.516192Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=pdf_text observed=2026-05-12T02:27:06.805794Z digest=sha256:b8d1cd26e6c973eb16c40f09f4737d6bfcac1a925a4961c30705b315e8a6f256

Observation e5ae8687-91ee-45b4-8f28-3f6b75a3ec47 · inbound

REALISTA: Realistic Latent Adversarial Attacks that Elicit LLM Hallucinations cites this paper.

REALISTA: Realistic Latent Adversarial Attacks that Elicit LLM Hallucinations PoisonedRAG: Knowledge Corruption Attacks to Retrieval-Augmented Generation of Large Language Models

Reference 179

Resolution
metadata mismatch
arxiv_id, observed 2026-05-14T20:19:26.554033Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=arxiv_source observed=2026-05-14T20:13:10.814899Z digest=sha256:370a580593392e2c35007ad7f1c4df6017bcc84f9a76431ef3f3daf28b05c4b7

Observation 45ed2b15-873e-4dfb-9ce6-ecfbc07f8d83 · inbound

VectorSmuggle: Steganographic Exfiltration in Embedding Stores and a Cryptographic Provenance Defense cites this paper.

VectorSmuggle: Steganographic Exfiltration in Embedding Stores and a Cryptographic Provenance Defense PoisonedRAG: Knowledge Corruption Attacks to Retrieval-Augmented Generation of Large Language Models

Reference 35

Resolution
verified exact
arxiv_id, observed 2026-05-14T17:47:32.233883Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=pdf_text observed=2026-05-14T17:45:53.847798Z digest=sha256:65fbb86e822300148e3b0893d9c56fe1dd5c8d342a1a8330ba5912351da20102

Observation d7265b92-4d31-4e5e-b7af-50e8724504ef · inbound

Does RAG Know When Retrieval Is Wrong? Diagnosing Context Compliance under Knowledge Conflict cites this paper.

Does RAG Know When Retrieval Is Wrong? Diagnosing Context Compliance under Knowledge Conflict PoisonedRAG: Knowledge Corruption Attacks to Retrieval-Augmented Generation of Large Language Models

Reference 19

Resolution
verified exact
arxiv_id, observed 2026-05-15T02:03:28.746771Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=pdf_text observed=2026-05-15T02:03:23.662430Z digest=sha256:d7a5eebdb63126fd40c83017fd9bd68621fd85d8c99b112ebe9f2b7518d6d11b

Observation 38930f4c-36e1-4979-a90e-32f38d2c8fbe · inbound

Does RAG Know When Retrieval Is Wrong? Diagnosing Context Compliance under Knowledge Conflict cites this paper.

Does RAG Know When Retrieval Is Wrong? Diagnosing Context Compliance under Knowledge Conflict PoisonedRAG: Knowledge Corruption Attacks to Retrieval-Augmented Generation of Large Language Models

Reference 19

Resolution
verified exact
arxiv_id, observed 2026-05-19T16:42:39.900319Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=pdf_text observed=2026-05-19T16:38:32.946287Z digest=sha256:7030efe55832fb9abc6b53529b478a2d29dbcc0240da9ab34e39ec8864f62696

Observation 287ada0c-ae60-400a-a549-643165fec13f · inbound

Taxonomy and Consistency Analysis of Safety Benchmarks for AI Agents cites this paper.

Taxonomy and Consistency Analysis of Safety Benchmarks for AI Agents PoisonedRAG: Knowledge Corruption Attacks to Retrieval-Augmented Generation of Large Language Models

Reference 71

Resolution
verified exact
arxiv_id, observed 2026-05-21T01:43:56.674346Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=arxiv_source observed=2026-05-21T01:42:55.693115Z digest=sha256:3b500d8d44ff4deea27ac4b39f60f144d5ba648434496d2c0f19fd402ce83497

Observation 9e07f974-dc47-4ebf-9248-a12082270142 · inbound

An Empirical Study of Privacy Leakage Chains via Prompt Injection in Black-Box Chatbot Environments cites this paper.

An Empirical Study of Privacy Leakage Chains via Prompt Injection in Black-Box Chatbot Environments PoisonedRAG: Knowledge Corruption Attacks to Retrieval-Augmented Generation of Large Language Models

Reference 21

Resolution
verified exact
arxiv_id, observed 2026-05-20T09:58:10.849558Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=pdf_text observed=2026-05-20T09:58:05.349147Z digest=sha256:65feef5305114fd34f7e54b2bdd904d06748ca687af79846713730996b6133df

Observation 66f274a4-c16b-4c99-87fd-6af7e1c49e35 · inbound

Detecting Is Not Resolving: The Monitoring Control Gap in Retrieval Augmented LLMs cites this paper.

Detecting Is Not Resolving: The Monitoring Control Gap in Retrieval Augmented LLMs PoisonedRAG: Knowledge Corruption Attacks to Retrieval-Augmented Generation of Large Language Models

Reference 14

Resolution
verified exact
arxiv_id, observed 2026-06-29T17:13:44.829559Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=arxiv_source observed=2026-06-29T17:06:46.379906Z digest=sha256:7663e62c84b5d4c02a808938964fc2f8b39a60f2a4d21475e217f2b80a92e381

Observation 46fa93b4-522d-4d55-821f-8105162fdbdd · inbound

Adversarial Feeds Steer LLM Agent Decisions Against Their Defaults cites this paper.

Adversarial Feeds Steer LLM Agent Decisions Against Their Defaults PoisonedRAG: Knowledge Corruption Attacks to Retrieval-Augmented Generation of Large Language Models

Reference 5

Resolution
metadata mismatch
arxiv_id, observed 2026-06-28T20:52:38.003084Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=arxiv_source observed=2026-06-28T18:18:52.472535Z digest=sha256:20b688f74da2fc6d55938a75f9dbf5ca49da50db6a44cbd3f0eacb2c886c1a43

Observation 45c9ff80-9322-49db-b96a-947086b15ac3 · inbound

DiscourseFlip: An Oblique Discourse-Level Opinion Manipulation Attack against Black-box Retrieval-Augmented Generation cites this paper.

DiscourseFlip: An Oblique Discourse-Level Opinion Manipulation Attack against Black-box Retrieval-Augmented Generation PoisonedRAG: Knowledge Corruption Attacks to Retrieval-Augmented Generation of Large Language Models

Reference 50

Resolution
malformed identifier
arxiv_id, observed 2026-07-01T20:46:13.945971Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=pdf_text observed=2026-06-28T17:43:41.256808Z digest=sha256:24f9c4ee46e5d93bc01342de914586a522c5daf58274c8d1eb02aa6828a8bbfd

Observation 89906a3a-5bb4-4419-8479-98f97d714282 · inbound

Inference Cost Attacks for Retrieval-Augmented Large Language Models cites this paper.

Inference Cost Attacks for Retrieval-Augmented Large Language Models PoisonedRAG: Knowledge Corruption Attacks to Retrieval-Augmented Generation of Large Language Models

Reference 44

Resolution
verified exact
arxiv_id, observed 2026-06-28T17:02:23.695671Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=pdf_text observed=2026-06-28T16:55:50.702951Z digest=sha256:9c76a2c24b3a633d210be45c2af36eeb65870cd8c26549f643bb8f562491be38

Observation 37192de0-f434-44cf-b19a-6dd213da2a6b · inbound

Discourse-Role Labels as Presentation-Time Variables for Context Use in Language Models cites this paper.

Discourse-Role Labels as Presentation-Time Variables for Context Use in Language Models PoisonedRAG: Knowledge Corruption Attacks to Retrieval-Augmented Generation of Large Language Models

Reference 16

Resolution
metadata mismatch
arxiv_id, observed 2026-07-02T03:16:33.694948Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=pdf_text observed=2026-06-28T10:13:48.860754Z digest=sha256:0872743135306103e0955c2716a8d0d37b018b36207cd6d395c488d1f9420090

Observation 2ff323c7-24cd-455f-a83e-62ff87bbc5a2 · inbound

Game-Theoretic Multi-Agent Control for Robust Contextual Reasoning in LLMs cites this paper.

Game-Theoretic Multi-Agent Control for Robust Contextual Reasoning in LLMs PoisonedRAG: Knowledge Corruption Attacks to Retrieval-Augmented Generation of Large Language Models

Reference 16

Resolution
verified exact
arxiv_id, observed 2026-07-03T05:47:41.232114Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=pdf_text observed=2026-06-27T13:05:57.618969Z digest=sha256:4757a7ec26ade890a90560f0acc894eda24de1d5b4dc4ee42e17682b646a4e6b

Observation 4487f155-8f59-4119-a4ba-e9525daccaa3 · inbound

Selection Integrity for LLM Graph Memory: An Accumulability Criterion for Information-Flow-Blind Retrieval cites this paper.

Selection Integrity for LLM Graph Memory: An Accumulability Criterion for Information-Flow-Blind Retrieval PoisonedRAG: Knowledge Corruption Attacks to Retrieval-Augmented Generation of Large Language Models

Reference 19

Resolution
verified exact
arxiv_id, observed 2026-07-03T11:58:06.301450Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=pdf_text observed=2026-06-27T09:13:58.485088Z digest=sha256:c0ed64a2ed4fdd60575dae61f1df3c2011b44f727ed1c3a3d0e6f66f780915f7

Observation 453d6083-7bfc-4e6a-9955-d2f3a298ec65 · inbound

SafeClawBench: Separating Semantic, Audit-Evidence, and Sandbox Harm in Tool-Using LLM Agents cites this paper.

SafeClawBench: Separating Semantic, Audit-Evidence, and Sandbox Harm in Tool-Using LLM Agents PoisonedRAG: Knowledge Corruption Attacks to Retrieval-Augmented Generation of Large Language Models

Reference 42

Resolution
malformed identifier
arxiv_id, observed 2026-07-03T22:18:59.754139Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=pdf_text observed=2026-06-26T23:40:53.439549Z digest=sha256:6243c82cbb9816b7ac39e74e05112e8acc60cf183ae3b0cae39e7d4a6d97b814

Observation 5afa86ac-e448-4b11-b5aa-400ec67eb303 · inbound

ARENA: An Architecture for Measuring the Transferability of Autonomous Cyber Defense cites this paper.

ARENA: An Architecture for Measuring the Transferability of Autonomous Cyber Defense PoisonedRAG: Knowledge Corruption Attacks to Retrieval-Augmented Generation of Large Language Models

Reference 36

Resolution
verified exact
arxiv_id, observed 2026-07-04T06:59:37.745250Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=pdf_text observed=2026-06-26T14:00:04.412804Z digest=sha256:140ede092908d4ee5c32535384987388f01c94fcadee9649f473fa3415f82a4b

Observation b0d4382c-c9bb-41d4-a1bf-4416dc997355 · inbound

Evidence-Bound Gateway-Path Provenance for Third-Party LLM Inference cites this paper.

Evidence-Bound Gateway-Path Provenance for Third-Party LLM Inference PoisonedRAG: Knowledge Corruption Attacks to Retrieval-Augmented Generation of Large Language Models

Reference 44

Resolution
verified exact
arxiv_id, observed 2026-07-04T09:19:44.154540Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=pdf_text observed=2026-06-26T10:07:23.015655Z digest=sha256:347ed07f4c91413bfe1e8471391d0c90d4578433e7489029819fe7a77009db9f

Observation 69d17ae0-f5fd-443a-ac00-345c2f54c9ba · inbound

Securing LLM-Agent Long-Term Memory Against Poisoning: Non-Malleable, Origin-Bound Authority with Machine-Checked Guarantees cites this paper.

Securing LLM-Agent Long-Term Memory Against Poisoning: Non-Malleable, Origin-Bound Authority with Machine-Checked Guarantees PoisonedRAG: Knowledge Corruption Attacks to Retrieval-Augmented Generation of Large Language Models

Reference 9

Resolution
verified exact
arxiv_id, observed 2026-07-04T17:30:00.240682Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=pdf_text observed=2026-06-25T23:40:36.181525Z digest=sha256:256d72a807b557dd663eb7d5d6269e35681f18128cb92bc66b6ba11411a38806

Observation a1ac8142-e97a-44a1-8f5b-ea1b6601fa40 · inbound

ToE: A Hierarchical and Explainable Claim Verification Framework with Dynamic Multi-source Evidence Retrieval and Aggregation cites this paper.

ToE: A Hierarchical and Explainable Claim Verification Framework with Dynamic Multi-source Evidence Retrieval and Aggregation PoisonedRAG: Knowledge Corruption Attacks to Retrieval-Augmented Generation of Large Language Models

Reference 6

Resolution
verified exact
arxiv_id, observed 2026-06-29T18:43:51.201286Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=pdf_text observed=2026-06-29T05:03:26.118083Z digest=sha256:ac3b39f17f94e881ee5e9bd277b8fbaf87658d030bd42b57ce452d3acb7e5cc4

Observation 8f5984e1-77ec-42ae-876e-74232566ef7f · inbound

A Lifecycle and Application-Stack Survey of Large Language Model Vulnerabilities: Attacks, Risks, Defenses, and Open Problems cites this paper.

A Lifecycle and Application-Stack Survey of Large Language Model Vulnerabilities: Attacks, Risks, Defenses, and Open Problems PoisonedRAG: Knowledge Corruption Attacks to Retrieval-Augmented Generation of Large Language Models

Reference 33

Resolution
verified exact
arxiv_id, observed 2026-07-01T11:05:42.295805Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=pdf_text observed=2026-07-01T04:44:23.543728Z digest=sha256:cd9fa3f915a8b5742c7fe3a7d4bb8409c4fb891501d39fd8ad64a897d20d7b46

Observation ccb137ec-5bdf-4865-a728-3a2b5fe49bbc · inbound

Self-Study Reconsidered: The Hidden Fragility of Learning from Self-Generated QA cites this paper.

Self-Study Reconsidered: The Hidden Fragility of Learning from Self-Generated QA PoisonedRAG: Knowledge Corruption Attacks to Retrieval-Augmented Generation of Large Language Models

Reference 41

Resolution
verified exact
arxiv_id, observed 2026-07-01T10:45:42.842605Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=pdf_text observed=2026-07-01T05:07:58.441326Z digest=sha256:ae90bb45673d949b9326ecdbcb66df6e2853e552f5bc717f3e852fe2c4a9b77e

Observation 3ee26914-5863-4dd5-be2d-2aa90f5427c4 · inbound

PRA-RAG: Provably Robust Aggregation in Retrieval-Augmented Generation against Retrieval Corruption cites this paper.

PRA-RAG: Provably Robust Aggregation in Retrieval-Augmented Generation against Retrieval Corruption PoisonedRAG: Knowledge Corruption Attacks to Retrieval-Augmented Generation of Large Language Models

Reference 136

Resolution
verified exact
arxiv_id, observed 2026-07-02T23:47:27.220715Z

Source-reported events for the cited work

No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.

source=arxiv_source observed=2026-07-02T23:42:23.695930Z digest=sha256:0e1ae8df086a8c737348a73e1f98e002aedd6444ad40f6a62b46f733678fd0b8

Observation ee90f312-5107-411e-a5a3-e2e13e65d86b · inbound

Operational Evidence Gaps for LLMs in Fraud Detection and Trust-and-Safety Workflows cites this paper.

Operational Evidence Gaps for LLMs in Fraud Detection and Trust-and-Safety Workflows PoisonedRAG: Knowledge Corruption Attacks to Retrieval-Augmented Generation of Large Language Models

Reference 13

Resolution
unresolved
no resolver link, observed 2026-08-02T07:06:19.177718Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T07:06:19.177718Z digest=sha256:74184209f14e6541de610414de14c5e6a46620445360f4955d307bd0dc45d008

Observation 32a749b5-8c39-4202-9b3d-8631a058f76d · inbound

Certified Domain Consistency for Multi-Domain Retrieval: Label-Free Per-Domain Contamination Control with Conformal Risk Guarantees cites this paper.

Certified Domain Consistency for Multi-Domain Retrieval: Label-Free Per-Domain Contamination Control with Conformal Risk Guarantees PoisonedRAG: Knowledge Corruption Attacks to Retrieval-Augmented Generation of Large Language Models

Reference 63

Resolution
unresolved
no resolver link, observed 2026-08-02T05:55:34.871634Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-02T05:55:34.871634Z digest=sha256:a1471e5472fdefcc0e0e7c333c68a8a6967165203291cfd756a267d028515bf8

Observation e6e5ca80-4ad2-4309-9b65-ca2a9cffba0e · inbound

GPE: Evaluating Robust Evidence Aggregation for Fact Verification under Controllable GEO-Style Poisoning cites this paper.

GPE: Evaluating Robust Evidence Aggregation for Fact Verification under Controllable GEO-Style Poisoning PoisonedRAG: Knowledge Corruption Attacks to Retrieval-Augmented Generation of Large Language Models

Reference 12

Resolution
unresolved
no resolver link, observed 2026-08-01T09:35:38.121521Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-01T09:35:38.121521Z digest=sha256:cf40bb9722a103ce51c8bc26abda8af509e08f8170989df5d3d0ef769dc24b76

Observation 1034e036-5d35-4e13-90d1-5b38feac677c · inbound

TriShieldRAG: A Three-Ring Defense-in-Depth Framework Against Knowledge Corruption in Retrieval-Augmented Generation cites this paper.

TriShieldRAG: A Three-Ring Defense-in-Depth Framework Against Knowledge Corruption in Retrieval-Augmented Generation PoisonedRAG: Knowledge Corruption Attacks to Retrieval-Augmented Generation of Large Language Models

Reference 2

Resolution
unresolved
no resolver link, observed 2026-07-30T10:56:48.053139Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-07-30T10:56:48.053139Z digest=sha256:4a5a1f6115ddfec4ed24764705aa8b315a3c5bf2554ec70db5dc35cc472bdacd

Observation b762fbc8-2f22-4c04-afaf-36ca9dbed0c2 · inbound

Securing Agentic AI: From Per-Action Checks to Trajectory Assurance cites this paper.

Securing Agentic AI: From Per-Action Checks to Trajectory Assurance PoisonedRAG: Knowledge Corruption Attacks to Retrieval-Augmented Generation of Large Language Models

Reference 55

Resolution
unresolved
no resolver link, observed 2026-08-07T00:12:27.078558Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-07T00:12:27.078558Z digest=sha256:ad68f7e272e8f8abcdc28b3a3a3198af3ff42f72df9ee4eb09eff4cfce1545ff

Observation 02de363d-cea2-47f3-8fb4-68505a5bb3e8 · inbound

Understanding Sparse Attention Selectivity in Long-Context Foundation Models via Counterfactual Evaluation cites this paper.

Understanding Sparse Attention Selectivity in Long-Context Foundation Models via Counterfactual Evaluation PoisonedRAG: Knowledge Corruption Attacks to Retrieval-Augmented Generation of Large Language Models

Reference 10

Resolution
unresolved
no resolver link, observed 2026-08-04T23:14:59.401573Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-04T23:14:59.401573Z digest=sha256:1ef55bc587b1bf55b967fabfdee33f37bcc49ba8d19cc3c46b6b455f49268e29

Observation 3c4cb171-c8d0-46ff-a2e8-23461687a134 · inbound

Combating Knowledge Corruption in Agent Systems: A Byzantine-Tolerant Secure Collaborative RAG Framework cites this paper.

Combating Knowledge Corruption in Agent Systems: A Byzantine-Tolerant Secure Collaborative RAG Framework PoisonedRAG: Knowledge Corruption Attacks to Retrieval-Augmented Generation of Large Language Models

Reference 8

Resolution
unresolved
no resolver link, observed 2026-08-08T18:59:12.538220Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=pdf_text observed=2026-08-08T18:59:12.538220Z digest=sha256:2a284b9729d6f61fc65db0fbee877ed9626f50975db5eeb9ed61d6151e5791bf

Observation 8a1d15d4-8840-46d8-9878-f032fcf9c810 · inbound

Persistent Semantic Entities in Tool-Augmented LLM Systems cites this paper.

Persistent Semantic Entities in Tool-Augmented LLM Systems PoisonedRAG: Knowledge Corruption Attacks to Retrieval-Augmented Generation of Large Language Models

Reference 37

Resolution
unresolved
no resolver link, observed 2026-08-12T00:47:18.135511Z

Source-reported events for the cited work

Unavailable: canonical work link unavailable.

source=arxiv_source observed=2026-08-12T00:47:18.135511Z digest=sha256:6cedf1f96933008f95d5fc390aeb00fd13d202c0c1c47cabac86cb93d2df7dca