{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2024:2X5LMA24JSV52A4Y5CBWCJH4BO","short_pith_number":"pith:2X5LMA24","schema_version":"1.0","canonical_sha256":"d5fab6035c4cabdd0398e8836124fc0b9f98ae845f7f0fe3f16fe1a5ad5b86ce","source":{"kind":"arxiv","id":"2410.14479","version":1},"attestation_state":"computed","paper":{"title":"Backdoored Retrievers for Prompt Injection Attacks on Retrieval Augmented Generation of Large Language Models","license":"http://creativecommons.org/licenses/by-nc-sa/4.0/","headline":"","cross_cats":["cs.LG"],"primary_cat":"cs.CR","authors_text":"Cody Clop, Yannick Teglia","submitted_at":"2024-10-18T14:02:34Z","abstract_excerpt":"Large Language Models (LLMs) have demonstrated remarkable capabilities in generating coherent text but remain limited by the static nature of their training data. Retrieval Augmented Generation (RAG) addresses this issue by combining LLMs with up-to-date information retrieval, but also expand the attack surface of the system. This paper investigates prompt injection attacks on RAG, focusing on malicious objectives beyond misinformation, such as inserting harmful links, promoting unauthorized services, and initiating denial-of-service behaviors. We build upon existing corpus poisoning technique"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2410.14479","kind":"arxiv","version":1},"metadata":{"license":"http://creativecommons.org/licenses/by-nc-sa/4.0/","primary_cat":"cs.CR","submitted_at":"2024-10-18T14:02:34Z","cross_cats_sorted":["cs.LG"],"title_canon_sha256":"57274fd75350469f67837b27418f882611934fb60a68f2e9a52508baa11b92da","abstract_canon_sha256":"151665affb2cbab909c713be6c7acf6afc8e68918d7fc7cfac9de532be0fe0c1"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T09:22:32.969819Z","signature_b64":"y2XE5SmDbpxvEwfZCxrSQuBXxpj0uQpUIbcGL6BlYqY2vNlZ+mHtAXgKNdwVbfbqfo16ozK9BUhYobxCH/v2Dw==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"d5fab6035c4cabdd0398e8836124fc0b9f98ae845f7f0fe3f16fe1a5ad5b86ce","last_reissued_at":"2026-07-05T09:22:32.969410Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T09:22:32.969410Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Backdoored Retrievers for Prompt Injection Attacks on Retrieval Augmented Generation of Large Language Models","license":"http://creativecommons.org/licenses/by-nc-sa/4.0/","headline":"","cross_cats":["cs.LG"],"primary_cat":"cs.CR","authors_text":"Cody Clop, Yannick Teglia","submitted_at":"2024-10-18T14:02:34Z","abstract_excerpt":"Large Language Models (LLMs) have demonstrated remarkable capabilities in generating coherent text but remain limited by the static nature of their training data. Retrieval Augmented Generation (RAG) addresses this issue by combining LLMs with up-to-date information retrieval, but also expand the attack surface of the system. This paper investigates prompt injection attacks on RAG, focusing on malicious objectives beyond misinformation, such as inserting harmful links, promoting unauthorized services, and initiating denial-of-service behaviors. We build upon existing corpus poisoning technique"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2410.14479","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2410.14479/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2410.14479","created_at":"2026-07-05T09:22:32.969464+00:00"},{"alias_kind":"arxiv_version","alias_value":"2410.14479v1","created_at":"2026-07-05T09:22:32.969464+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2410.14479","created_at":"2026-07-05T09:22:32.969464+00:00"},{"alias_kind":"pith_short_12","alias_value":"2X5LMA24JSV5","created_at":"2026-07-05T09:22:32.969464+00:00"},{"alias_kind":"pith_short_16","alias_value":"2X5LMA24JSV52A4Y","created_at":"2026-07-05T09:22:32.969464+00:00"},{"alias_kind":"pith_short_8","alias_value":"2X5LMA24","created_at":"2026-07-05T09:22:32.969464+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":7,"internal_anchor_count":0,"sample":[{"citing_arxiv_id":"2606.25533","citing_title":"Security and Privacy in Retrieval-Augmented Generation: Architectures, Threats, Defenses, and Future Directions for Building Trustworthy Systems","ref_index":40,"is_internal_anchor":false},{"citing_arxiv_id":"2606.18310","citing_title":"Conflict-Aware Retriever Editing for Knowledge Injection Attacks on LLM-Based RAG Systems","ref_index":13,"is_internal_anchor":false},{"citing_arxiv_id":"2606.09038","citing_title":"Personalization Meets Safety:Mechanisms,Risks,and Mitigations in Personalized LLMs","ref_index":29,"is_internal_anchor":false},{"citing_arxiv_id":"2605.22041","citing_title":"RADAR: Defending RAG Dynamically against Retrieval Corruption","ref_index":2,"is_internal_anchor":false},{"citing_arxiv_id":"2510.23883","citing_title":"Agentic AI Security: Threats, Defenses, Evaluation, and Open Challenges","ref_index":78,"is_internal_anchor":false},{"citing_arxiv_id":"2605.08442","citing_title":"Injection-Execution Dissociation: A Mechanistic Evaluation of Persistent Memory Attacks and Defenses in Stateful LLM Agents","ref_index":20,"is_internal_anchor":false},{"citing_arxiv_id":"2605.01782","citing_title":"Needle-in-RAG: Prompt-Conditioned Character-Level Traceback of Poisoned Spans in Retrieved Evidence","ref_index":16,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/2X5LMA24JSV52A4Y5CBWCJH4BO","json":"https://pith.science/pith/2X5LMA24JSV52A4Y5CBWCJH4BO.json","graph_json":"https://pith.science/api/pith-number/2X5LMA24JSV52A4Y5CBWCJH4BO/graph.json","events_json":"https://pith.science/api/pith-number/2X5LMA24JSV52A4Y5CBWCJH4BO/events.json","paper":"https://pith.science/paper/2X5LMA24"},"agent_actions":{"view_html":"https://pith.science/pith/2X5LMA24JSV52A4Y5CBWCJH4BO","download_json":"https://pith.science/pith/2X5LMA24JSV52A4Y5CBWCJH4BO.json","view_paper":"https://pith.science/paper/2X5LMA24","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2410.14479&json=true","fetch_graph":"https://pith.science/api/pith-number/2X5LMA24JSV52A4Y5CBWCJH4BO/graph.json","fetch_events":"https://pith.science/api/pith-number/2X5LMA24JSV52A4Y5CBWCJH4BO/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/2X5LMA24JSV52A4Y5CBWCJH4BO/action/timestamp_anchor","attest_storage":"https://pith.science/pith/2X5LMA24JSV52A4Y5CBWCJH4BO/action/storage_attestation","attest_author":"https://pith.science/pith/2X5LMA24JSV52A4Y5CBWCJH4BO/action/author_attestation","sign_citation":"https://pith.science/pith/2X5LMA24JSV52A4Y5CBWCJH4BO/action/citation_signature","submit_replication":"https://pith.science/pith/2X5LMA24JSV52A4Y5CBWCJH4BO/action/replication_record"}},"created_at":"2026-07-05T09:22:32.969464+00:00","updated_at":"2026-07-05T09:22:32.969464+00:00"}