{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2024:RJNDDW7NZIIALFAH6XNZUAS3LZ","short_pith_number":"pith:RJNDDW7N","schema_version":"1.0","canonical_sha256":"8a5a31dbedca10059407f5db9a025b5e4f29ab3e0d0f60db50dbeb1b2e6e6722","source":{"kind":"arxiv","id":"2411.18948","version":5},"attestation_state":"computed","paper":{"title":"RevPRAG: Revealing Poisoning Attacks in Retrieval-Augmented Generation through LLM Activation Analysis","license":"http://creativecommons.org/licenses/by-sa/4.0/","headline":"","cross_cats":["cs.AI"],"primary_cat":"cs.CR","authors_text":"Hao Luan, Jun Dai, Mingyu Luo, Ping Chen, Xiaoyan Sun, Xue Tan","submitted_at":"2024-11-28T06:29:46Z","abstract_excerpt":"Retrieval-Augmented Generation (RAG) enriches the input to LLMs by retrieving information from the relevant knowledge database, enabling them to produce responses that are more accurate and contextually appropriate. It is worth noting that the knowledge database, being sourced from publicly available channels such as Wikipedia, inevitably introduces a new attack surface. RAG poisoning involves injecting malicious texts into the knowledge database, ultimately leading to the generation of the attacker's target response (also called poisoned response). However, there are currently limited methods"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2411.18948","kind":"arxiv","version":5},"metadata":{"license":"http://creativecommons.org/licenses/by-sa/4.0/","primary_cat":"cs.CR","submitted_at":"2024-11-28T06:29:46Z","cross_cats_sorted":["cs.AI"],"title_canon_sha256":"d3bf6cdc5c7a129467f160997452bc4b4ec6a66a64522b491cfa78a305dbca40","abstract_canon_sha256":"6025f9bccf3c21585ed3fea9a3808b1ca4233b6e80601c78c517ae7aab9e544c"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T12:01:20.045625Z","signature_b64":"l1AjZ9XQICQHkDYbEGsIW8GCg63b9iha79VStadGKNv5VFTmrbe5rK1HQkFYOoIzMfkjN/m7M/DDtmOjcouWAg==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"8a5a31dbedca10059407f5db9a025b5e4f29ab3e0d0f60db50dbeb1b2e6e6722","last_reissued_at":"2026-07-05T12:01:20.045126Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T12:01:20.045126Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"RevPRAG: Revealing Poisoning Attacks in Retrieval-Augmented Generation through LLM Activation Analysis","license":"http://creativecommons.org/licenses/by-sa/4.0/","headline":"","cross_cats":["cs.AI"],"primary_cat":"cs.CR","authors_text":"Hao Luan, Jun Dai, Mingyu Luo, Ping Chen, Xiaoyan Sun, Xue Tan","submitted_at":"2024-11-28T06:29:46Z","abstract_excerpt":"Retrieval-Augmented Generation (RAG) enriches the input to LLMs by retrieving information from the relevant knowledge database, enabling them to produce responses that are more accurate and contextually appropriate. It is worth noting that the knowledge database, being sourced from publicly available channels such as Wikipedia, inevitably introduces a new attack surface. RAG poisoning involves injecting malicious texts into the knowledge database, ultimately leading to the generation of the attacker's target response (also called poisoned response). However, there are currently limited methods"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2411.18948","kind":"arxiv","version":5},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2411.18948/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2411.18948","created_at":"2026-07-05T12:01:20.045184+00:00"},{"alias_kind":"arxiv_version","alias_value":"2411.18948v5","created_at":"2026-07-05T12:01:20.045184+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2411.18948","created_at":"2026-07-05T12:01:20.045184+00:00"},{"alias_kind":"pith_short_12","alias_value":"RJNDDW7NZIIA","created_at":"2026-07-05T12:01:20.045184+00:00"},{"alias_kind":"pith_short_16","alias_value":"RJNDDW7NZIIALFAH","created_at":"2026-07-05T12:01:20.045184+00:00"},{"alias_kind":"pith_short_8","alias_value":"RJNDDW7N","created_at":"2026-07-05T12:01:20.045184+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":6,"internal_anchor_count":1,"sample":[{"citing_arxiv_id":"2607.06807","citing_title":"When Agents Go Rogue: Activation-Based Detection of Malicious Behaviors in Multi-Agent Systems","ref_index":14,"is_internal_anchor":true},{"citing_arxiv_id":"2605.03482","citing_title":"MEMSAD: Gradient-Coupled Anomaly Detection for Memory Poisoning in Retrieval-Augmented Agents","ref_index":11,"is_internal_anchor":false},{"citing_arxiv_id":"2605.01782","citing_title":"Needle-in-RAG: Prompt-Conditioned Character-Level Traceback of Poisoned Spans in Retrieved Evidence","ref_index":47,"is_internal_anchor":false},{"citing_arxiv_id":"2605.06812","citing_title":"Towards Security-Auditable LLM Agents: A Unified Graph Representation","ref_index":55,"is_internal_anchor":false},{"citing_arxiv_id":"2605.02187","citing_title":"Rewriting the Response Path: Silent Tampering and Provider-Signed Defense in BYOK LLM Agents","ref_index":90,"is_internal_anchor":false},{"citing_arxiv_id":"2605.03482","citing_title":"MEMSAD: Gradient-Coupled Anomaly Detection for Memory Poisoning in Retrieval-Augmented Agents","ref_index":11,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/RJNDDW7NZIIALFAH6XNZUAS3LZ","json":"https://pith.science/pith/RJNDDW7NZIIALFAH6XNZUAS3LZ.json","graph_json":"https://pith.science/api/pith-number/RJNDDW7NZIIALFAH6XNZUAS3LZ/graph.json","events_json":"https://pith.science/api/pith-number/RJNDDW7NZIIALFAH6XNZUAS3LZ/events.json","paper":"https://pith.science/paper/RJNDDW7N"},"agent_actions":{"view_html":"https://pith.science/pith/RJNDDW7NZIIALFAH6XNZUAS3LZ","download_json":"https://pith.science/pith/RJNDDW7NZIIALFAH6XNZUAS3LZ.json","view_paper":"https://pith.science/paper/RJNDDW7N","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2411.18948&json=true","fetch_graph":"https://pith.science/api/pith-number/RJNDDW7NZIIALFAH6XNZUAS3LZ/graph.json","fetch_events":"https://pith.science/api/pith-number/RJNDDW7NZIIALFAH6XNZUAS3LZ/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/RJNDDW7NZIIALFAH6XNZUAS3LZ/action/timestamp_anchor","attest_storage":"https://pith.science/pith/RJNDDW7NZIIALFAH6XNZUAS3LZ/action/storage_attestation","attest_author":"https://pith.science/pith/RJNDDW7NZIIALFAH6XNZUAS3LZ/action/author_attestation","sign_citation":"https://pith.science/pith/RJNDDW7NZIIALFAH6XNZUAS3LZ/action/citation_signature","submit_replication":"https://pith.science/pith/RJNDDW7NZIIALFAH6XNZUAS3LZ/action/replication_record"}},"created_at":"2026-07-05T12:01:20.045184+00:00","updated_at":"2026-07-05T12:01:20.045184+00:00"}