{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2025:PEEJPTG3Y6JCK6BXN263RJSSRB","short_pith_number":"pith:PEEJPTG3","schema_version":"1.0","canonical_sha256":"790897ccdbc7922578376ebdb8a652887be8f26951b6c0704f34985b0b39cf93","source":{"kind":"arxiv","id":"2505.19864","version":1},"attestation_state":"computed","paper":{"title":"CPA-RAG:Covert Poisoning Attacks on Retrieval-Augmented Generation in Large Language Models","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":[],"primary_cat":"cs.CR","authors_text":"Anda Cheng, Chunyang Li, Jianfeng Ma, Junwei Zhang, Xinghua Li, Zhuo Ma","submitted_at":"2025-05-26T11:48:32Z","abstract_excerpt":"Retrieval-Augmented Generation (RAG) enhances large language models (LLMs) by incorporating external knowledge, but its openness introduces vulnerabilities that can be exploited by poisoning attacks. Existing poisoning methods for RAG systems have limitations, such as poor generalization and lack of fluency in adversarial texts. In this paper, we propose CPA-RAG, a black-box adversarial framework that generates query-relevant texts capable of manipulating the retrieval process to induce target answers. The proposed method integrates prompt-based text generation, cross-guided optimization throu"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2505.19864","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2025-05-26T11:48:32Z","cross_cats_sorted":[],"title_canon_sha256":"473fa277e632c82162064ffbd534621271daf2394e4c794640b4a53d6ae48d8a","abstract_canon_sha256":"cae73d95d730b07ef38f4e69d5582d3e22fdeef0882686ad1faaac65aac8242d"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T11:09:49.148555Z","signature_b64":"jxbgwhQMbOyGW949vF8PDI46r3DCE2gZfyNkV3SzXJYj63hDHrJDpB9BwI4M4UMrxQpjO7VITmtOnXLTtsZlDg==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"790897ccdbc7922578376ebdb8a652887be8f26951b6c0704f34985b0b39cf93","last_reissued_at":"2026-07-05T11:09:49.148048Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T11:09:49.148048Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"CPA-RAG:Covert Poisoning Attacks on Retrieval-Augmented Generation in Large Language Models","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":[],"primary_cat":"cs.CR","authors_text":"Anda Cheng, Chunyang Li, Jianfeng Ma, Junwei Zhang, Xinghua Li, Zhuo Ma","submitted_at":"2025-05-26T11:48:32Z","abstract_excerpt":"Retrieval-Augmented Generation (RAG) enhances large language models (LLMs) by incorporating external knowledge, but its openness introduces vulnerabilities that can be exploited by poisoning attacks. Existing poisoning methods for RAG systems have limitations, such as poor generalization and lack of fluency in adversarial texts. In this paper, we propose CPA-RAG, a black-box adversarial framework that generates query-relevant texts capable of manipulating the retrieval process to induce target answers. The proposed method integrates prompt-based text generation, cross-guided optimization throu"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2505.19864","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2505.19864/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2505.19864","created_at":"2026-07-05T11:09:49.148097+00:00"},{"alias_kind":"arxiv_version","alias_value":"2505.19864v1","created_at":"2026-07-05T11:09:49.148097+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2505.19864","created_at":"2026-07-05T11:09:49.148097+00:00"},{"alias_kind":"pith_short_12","alias_value":"PEEJPTG3Y6JC","created_at":"2026-07-05T11:09:49.148097+00:00"},{"alias_kind":"pith_short_16","alias_value":"PEEJPTG3Y6JCK6BX","created_at":"2026-07-05T11:09:49.148097+00:00"},{"alias_kind":"pith_short_8","alias_value":"PEEJPTG3","created_at":"2026-07-05T11:09:49.148097+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":5,"internal_anchor_count":0,"sample":[{"citing_arxiv_id":"2606.18310","citing_title":"Conflict-Aware Retriever Editing for Knowledge Injection Attacks on LLM-Based RAG Systems","ref_index":33,"is_internal_anchor":false},{"citing_arxiv_id":"2606.11265","citing_title":"When Poison Fails After Retrieval: Revisiting Corpus Poisoning under Chunking and Reranking Pipelines","ref_index":23,"is_internal_anchor":false},{"citing_arxiv_id":"2604.00387","citing_title":"RAGShield: Detecting Numerical Claim Manipulation in Government RAG Systems","ref_index":8,"is_internal_anchor":false},{"citing_arxiv_id":"2605.00460","citing_title":"CleanBase: Detecting Malicious Documents in RAG Knowledge Databases","ref_index":35,"is_internal_anchor":false},{"citing_arxiv_id":"2604.07403","citing_title":"RefineRAG: Word-Level Poisoning Attacks via Retriever-Guided Text Refinement","ref_index":17,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/PEEJPTG3Y6JCK6BXN263RJSSRB","json":"https://pith.science/pith/PEEJPTG3Y6JCK6BXN263RJSSRB.json","graph_json":"https://pith.science/api/pith-number/PEEJPTG3Y6JCK6BXN263RJSSRB/graph.json","events_json":"https://pith.science/api/pith-number/PEEJPTG3Y6JCK6BXN263RJSSRB/events.json","paper":"https://pith.science/paper/PEEJPTG3"},"agent_actions":{"view_html":"https://pith.science/pith/PEEJPTG3Y6JCK6BXN263RJSSRB","download_json":"https://pith.science/pith/PEEJPTG3Y6JCK6BXN263RJSSRB.json","view_paper":"https://pith.science/paper/PEEJPTG3","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2505.19864&json=true","fetch_graph":"https://pith.science/api/pith-number/PEEJPTG3Y6JCK6BXN263RJSSRB/graph.json","fetch_events":"https://pith.science/api/pith-number/PEEJPTG3Y6JCK6BXN263RJSSRB/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/PEEJPTG3Y6JCK6BXN263RJSSRB/action/timestamp_anchor","attest_storage":"https://pith.science/pith/PEEJPTG3Y6JCK6BXN263RJSSRB/action/storage_attestation","attest_author":"https://pith.science/pith/PEEJPTG3Y6JCK6BXN263RJSSRB/action/author_attestation","sign_citation":"https://pith.science/pith/PEEJPTG3Y6JCK6BXN263RJSSRB/action/citation_signature","submit_replication":"https://pith.science/pith/PEEJPTG3Y6JCK6BXN263RJSSRB/action/replication_record"}},"created_at":"2026-07-05T11:09:49.148097+00:00","updated_at":"2026-07-05T11:09:49.148097+00:00"}