{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2026:LDKDYQ2ZH4RXVHWVO2B44HHHEZ","short_pith_number":"pith:LDKDYQ2Z","schema_version":"1.0","canonical_sha256":"58d43c43593f237a9ed57683ce1ce7264c1f43f17d7f48432a98ca02a7348675","source":{"kind":"arxiv","id":"2607.00422","version":1},"attestation_state":"computed","paper":{"title":"KidnapRAG: A Black-Box Attack for Hijacking Reasoning in Agentic Retrieval-Augmented Generation Systems","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":[],"primary_cat":"cs.CR","authors_text":"Buru Chang, Chanwoo Choi, Eunmi Kim, Euntae Kim, Jinhee Jeong, Junseo Jang, Kyuho Lee, Myunggyo Oh, Youngsam Chun","submitted_at":"2026-07-01T04:32:17Z","abstract_excerpt":"Retrieval-Augmented Generation (RAG) systems are vulnerable to poisoning attacks that inject malicious documents into the retrieval process to manipulate model outputs. Recent Agentic RAG systems are more robust to such attacks because they iteratively perform retrieval and reasoning, allowing them to ignore weakly relevant poisoned documents and preserve the reasoning chain induced by the user query. However, existing attacks on Agentic RAG systems often assume white-box access to system prompts, reasoning traces, retrievers, or model parameters, limiting their applicability in realistic sett"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2607.00422","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2026-07-01T04:32:17Z","cross_cats_sorted":[],"title_canon_sha256":"0c0848f8f38aa4cb716df986f97955007088e619bc178fa3e589852b90115727","abstract_canon_sha256":"e569d61600eb4978e2b0b5e04f318a7bbef2c780460216b1399dc35afb0adcbf"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-02T01:17:42.927970Z","signature_b64":"tX5MuDEasann3h66w/COMLN/7nGoiDvSrFWlz44WrVC7sf7eTnxfOG+38iOVTgogz+SBeDfl60flltGRYsffAg==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"58d43c43593f237a9ed57683ce1ce7264c1f43f17d7f48432a98ca02a7348675","last_reissued_at":"2026-07-02T01:17:42.927629Z","signature_status":"signed_v1","first_computed_at":"2026-07-02T01:17:42.927629Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"KidnapRAG: A Black-Box Attack for Hijacking Reasoning in Agentic Retrieval-Augmented Generation Systems","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":[],"primary_cat":"cs.CR","authors_text":"Buru Chang, Chanwoo Choi, Eunmi Kim, Euntae Kim, Jinhee Jeong, Junseo Jang, Kyuho Lee, Myunggyo Oh, Youngsam Chun","submitted_at":"2026-07-01T04:32:17Z","abstract_excerpt":"Retrieval-Augmented Generation (RAG) systems are vulnerable to poisoning attacks that inject malicious documents into the retrieval process to manipulate model outputs. Recent Agentic RAG systems are more robust to such attacks because they iteratively perform retrieval and reasoning, allowing them to ignore weakly relevant poisoned documents and preserve the reasoning chain induced by the user query. However, existing attacks on Agentic RAG systems often assume white-box access to system prompts, reasoning traces, retrievers, or model parameters, limiting their applicability in realistic sett"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2607.00422","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2607.00422/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2607.00422","created_at":"2026-07-02T01:17:42.927690+00:00"},{"alias_kind":"arxiv_version","alias_value":"2607.00422v1","created_at":"2026-07-02T01:17:42.927690+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2607.00422","created_at":"2026-07-02T01:17:42.927690+00:00"},{"alias_kind":"pith_short_12","alias_value":"LDKDYQ2ZH4RX","created_at":"2026-07-02T01:17:42.927690+00:00"},{"alias_kind":"pith_short_16","alias_value":"LDKDYQ2ZH4RXVHWV","created_at":"2026-07-02T01:17:42.927690+00:00"},{"alias_kind":"pith_short_8","alias_value":"LDKDYQ2Z","created_at":"2026-07-02T01:17:42.927690+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":0,"internal_anchor_count":0,"sample":[]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/LDKDYQ2ZH4RXVHWVO2B44HHHEZ","json":"https://pith.science/pith/LDKDYQ2ZH4RXVHWVO2B44HHHEZ.json","graph_json":"https://pith.science/api/pith-number/LDKDYQ2ZH4RXVHWVO2B44HHHEZ/graph.json","events_json":"https://pith.science/api/pith-number/LDKDYQ2ZH4RXVHWVO2B44HHHEZ/events.json","paper":"https://pith.science/paper/LDKDYQ2Z"},"agent_actions":{"view_html":"https://pith.science/pith/LDKDYQ2ZH4RXVHWVO2B44HHHEZ","download_json":"https://pith.science/pith/LDKDYQ2ZH4RXVHWVO2B44HHHEZ.json","view_paper":"https://pith.science/paper/LDKDYQ2Z","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2607.00422&json=true","fetch_graph":"https://pith.science/api/pith-number/LDKDYQ2ZH4RXVHWVO2B44HHHEZ/graph.json","fetch_events":"https://pith.science/api/pith-number/LDKDYQ2ZH4RXVHWVO2B44HHHEZ/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/LDKDYQ2ZH4RXVHWVO2B44HHHEZ/action/timestamp_anchor","attest_storage":"https://pith.science/pith/LDKDYQ2ZH4RXVHWVO2B44HHHEZ/action/storage_attestation","attest_author":"https://pith.science/pith/LDKDYQ2ZH4RXVHWVO2B44HHHEZ/action/author_attestation","sign_citation":"https://pith.science/pith/LDKDYQ2ZH4RXVHWVO2B44HHHEZ/action/citation_signature","submit_replication":"https://pith.science/pith/LDKDYQ2ZH4RXVHWVO2B44HHHEZ/action/replication_record"}},"created_at":"2026-07-02T01:17:42.927690+00:00","updated_at":"2026-07-02T01:17:42.927690+00:00"}