{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2024:GZIPAPTEIVJZNW5ZMHFINALGOW","short_pith_number":"pith:GZIPAPTE","schema_version":"1.0","canonical_sha256":"3650f03e64455396dbb961ca86816675b1f8a9a5c037880611c42cfda28812e5","source":{"kind":"arxiv","id":"2405.13401","version":4},"attestation_state":"computed","paper":{"title":"TrojanRAG: Retrieval-Augmented Generation Can Be Backdoor Driver in Large Language Models","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.CL"],"primary_cat":"cs.CR","authors_text":"Gongshen Liu, Pengzhou Cheng, Ping Yi, Tianjie Ju, Wei Du, Yidong Ding, Zhuosheng Zhang, Zongru Wu","submitted_at":"2024-05-22T07:21:32Z","abstract_excerpt":"Large language models (LLMs) have raised concerns about potential security threats despite performing significantly in Natural Language Processing (NLP). Backdoor attacks initially verified that LLM is doing substantial harm at all stages, but the cost and robustness have been criticized. Attacking LLMs is inherently risky in security review, while prohibitively expensive. Besides, the continuous iteration of LLMs will degrade the robustness of backdoors. In this paper, we propose TrojanRAG, which employs a joint backdoor attack in the Retrieval-Augmented Generation, thereby manipulating LLMs "},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2405.13401","kind":"arxiv","version":4},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2024-05-22T07:21:32Z","cross_cats_sorted":["cs.CL"],"title_canon_sha256":"350e548ed5ad0899458afefd6535fdd26b76f0a95937c908576faea1e8a9604c","abstract_canon_sha256":"8a8bf3d32f6c9873a2579b78929d61624ad99600bb0a2cc39770d967c3f70182"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T08:41:03.092502Z","signature_b64":"RTm8yBwu5FjA37W6WvLooxwtUiGmuJFXIWqFtIExbOqcOQVJxbXCNM8YYbJpOz21Y0u7pkblwY6taXo/rWl6CA==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"3650f03e64455396dbb961ca86816675b1f8a9a5c037880611c42cfda28812e5","last_reissued_at":"2026-07-05T08:41:03.091894Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T08:41:03.091894Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"TrojanRAG: Retrieval-Augmented Generation Can Be Backdoor Driver in Large Language Models","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.CL"],"primary_cat":"cs.CR","authors_text":"Gongshen Liu, Pengzhou Cheng, Ping Yi, Tianjie Ju, Wei Du, Yidong Ding, Zhuosheng Zhang, Zongru Wu","submitted_at":"2024-05-22T07:21:32Z","abstract_excerpt":"Large language models (LLMs) have raised concerns about potential security threats despite performing significantly in Natural Language Processing (NLP). Backdoor attacks initially verified that LLM is doing substantial harm at all stages, but the cost and robustness have been criticized. Attacking LLMs is inherently risky in security review, while prohibitively expensive. Besides, the continuous iteration of LLMs will degrade the robustness of backdoors. In this paper, we propose TrojanRAG, which employs a joint backdoor attack in the Retrieval-Augmented Generation, thereby manipulating LLMs "},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2405.13401","kind":"arxiv","version":4},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2405.13401/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2405.13401","created_at":"2026-07-05T08:41:03.091966+00:00"},{"alias_kind":"arxiv_version","alias_value":"2405.13401v4","created_at":"2026-07-05T08:41:03.091966+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2405.13401","created_at":"2026-07-05T08:41:03.091966+00:00"},{"alias_kind":"pith_short_12","alias_value":"GZIPAPTEIVJZ","created_at":"2026-07-05T08:41:03.091966+00:00"},{"alias_kind":"pith_short_16","alias_value":"GZIPAPTEIVJZNW5Z","created_at":"2026-07-05T08:41:03.091966+00:00"},{"alias_kind":"pith_short_8","alias_value":"GZIPAPTE","created_at":"2026-07-05T08:41:03.091966+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":16,"internal_anchor_count":0,"sample":[{"citing_arxiv_id":"2606.24402","citing_title":"Poisoned Playbooks: Demystifying Knowledge Poisoning Effects on AI Security Agents","ref_index":30,"is_internal_anchor":false},{"citing_arxiv_id":"2606.18310","citing_title":"Conflict-Aware Retriever Editing for Knowledge Injection Attacks on LLM-Based RAG Systems","ref_index":12,"is_internal_anchor":false},{"citing_arxiv_id":"2607.00012","citing_title":"PRA-RAG: Provably Robust Aggregation in Retrieval-Augmented Generation against Retrieval Corruption","ref_index":20,"is_internal_anchor":false},{"citing_arxiv_id":"2606.01166","citing_title":"BraveGuard: From Open-World Threats to Safer Computer-Use Agents","ref_index":5,"is_internal_anchor":false},{"citing_arxiv_id":"2606.01212","citing_title":"DiscourseFlip: An Oblique Discourse-Level Opinion Manipulation Attack against Black-box Retrieval-Augmented Generation","ref_index":7,"is_internal_anchor":false},{"citing_arxiv_id":"2605.27157","citing_title":"Detecting Is Not Resolving: The Monitoring Control Gap in Retrieval Augmented LLMs","ref_index":26,"is_internal_anchor":false},{"citing_arxiv_id":"2605.28074","citing_title":"SilentRetrieval: Hijacking Retrieval-Augmented Generation via Semantically-Preserving Adversarial Data Poisoning","ref_index":7,"is_internal_anchor":false},{"citing_arxiv_id":"2409.10102","citing_title":"Trustworthiness in Retrieval-Augmented Generation Systems: A Survey","ref_index":82,"is_internal_anchor":false},{"citing_arxiv_id":"2501.13340","citing_title":"Retrievals Can Be Detrimental: Unveiling the Backdoor Vulnerability of Retrieval-Augmented Diffusion Models","ref_index":10,"is_internal_anchor":false},{"citing_arxiv_id":"2504.02181","citing_title":"A Survey of Scaling in Large Language Model Reasoning","ref_index":28,"is_internal_anchor":false},{"citing_arxiv_id":"2508.03793","citing_title":"AttnTrace: Contextual Attribution of Prompt Injection and Knowledge Corruption","ref_index":13,"is_internal_anchor":false},{"citing_arxiv_id":"2510.18333","citing_title":"Position: LLM Watermarking Should Align Stakeholders' Incentives for Practical Adoption","ref_index":8,"is_internal_anchor":false},{"citing_arxiv_id":"2604.28157","citing_title":"FlashRT: Towards Computationally and Memory Efficient Red-Teaming for Prompt Injection and Knowledge Corruption","ref_index":13,"is_internal_anchor":false},{"citing_arxiv_id":"2604.24700","citing_title":"Green Shielding: A User-Centric Approach Towards Trustworthy AI","ref_index":34,"is_internal_anchor":false},{"citing_arxiv_id":"2604.23483","citing_title":"Agentic Adversarial Rewriting Exposes Architectural Vulnerabilities in Black-Box NLP Pipelines","ref_index":41,"is_internal_anchor":false},{"citing_arxiv_id":"2604.06811","citing_title":"SkillTrojan: Backdoor Attacks on Skill-Based Agent Systems","ref_index":2,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/GZIPAPTEIVJZNW5ZMHFINALGOW","json":"https://pith.science/pith/GZIPAPTEIVJZNW5ZMHFINALGOW.json","graph_json":"https://pith.science/api/pith-number/GZIPAPTEIVJZNW5ZMHFINALGOW/graph.json","events_json":"https://pith.science/api/pith-number/GZIPAPTEIVJZNW5ZMHFINALGOW/events.json","paper":"https://pith.science/paper/GZIPAPTE"},"agent_actions":{"view_html":"https://pith.science/pith/GZIPAPTEIVJZNW5ZMHFINALGOW","download_json":"https://pith.science/pith/GZIPAPTEIVJZNW5ZMHFINALGOW.json","view_paper":"https://pith.science/paper/GZIPAPTE","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2405.13401&json=true","fetch_graph":"https://pith.science/api/pith-number/GZIPAPTEIVJZNW5ZMHFINALGOW/graph.json","fetch_events":"https://pith.science/api/pith-number/GZIPAPTEIVJZNW5ZMHFINALGOW/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/GZIPAPTEIVJZNW5ZMHFINALGOW/action/timestamp_anchor","attest_storage":"https://pith.science/pith/GZIPAPTEIVJZNW5ZMHFINALGOW/action/storage_attestation","attest_author":"https://pith.science/pith/GZIPAPTEIVJZNW5ZMHFINALGOW/action/author_attestation","sign_citation":"https://pith.science/pith/GZIPAPTEIVJZNW5ZMHFINALGOW/action/citation_signature","submit_replication":"https://pith.science/pith/GZIPAPTEIVJZNW5ZMHFINALGOW/action/replication_record"}},"created_at":"2026-07-05T08:41:03.091966+00:00","updated_at":"2026-07-05T08:41:03.091966+00:00"}