{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2024:U4WGGRMJ5DLNG76F35XPH5BALZ","short_pith_number":"pith:U4WGGRMJ","schema_version":"1.0","canonical_sha256":"a72c634589e8d6d37fc5df6ef3f4205e6ec4739989f19039dc056f24e4b6f1ea","source":{"kind":"arxiv","id":"2410.22832","version":1},"attestation_state":"computed","paper":{"title":"HijackRAG: Hijacking Attacks against Retrieval-Augmented Large Language Models","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.AI","cs.IR"],"primary_cat":"cs.CR","authors_text":"Jianwei Yin, Qinfeng Li, Tianyu Du, Xinkui Zhao, Xuhong Zhang, Yucheng Zhang, Zhengwen Feng","submitted_at":"2024-10-30T09:15:51Z","abstract_excerpt":"Retrieval-Augmented Generation (RAG) systems enhance large language models (LLMs) by integrating external knowledge, making them adaptable and cost-effective for various applications. However, the growing reliance on these systems also introduces potential security risks. In this work, we reveal a novel vulnerability, the retrieval prompt hijack attack (HijackRAG), which enables attackers to manipulate the retrieval mechanisms of RAG systems by injecting malicious texts into the knowledge database. When the RAG system encounters target questions, it generates the attacker's pre-determined answ"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2410.22832","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2024-10-30T09:15:51Z","cross_cats_sorted":["cs.AI","cs.IR"],"title_canon_sha256":"43a423edc7a5857af8d046e982e00255f572195d73dc8148f255994d5ff8886a","abstract_canon_sha256":"b70c23019140d35399952850922e1dc3ab423867e546e8c3dd37b6158f7e7a3f"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T09:28:36.836021Z","signature_b64":"TorxABusC7Gcaii/J8jUJs4Iu6xFr96RRfF7KJj3nTRC7pO1cHTnuEpX5FrlU/0g0lhrGXajdIT5AZyJ9kGJCw==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"a72c634589e8d6d37fc5df6ef3f4205e6ec4739989f19039dc056f24e4b6f1ea","last_reissued_at":"2026-07-05T09:28:36.835577Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T09:28:36.835577Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"HijackRAG: Hijacking Attacks against Retrieval-Augmented Large Language Models","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.AI","cs.IR"],"primary_cat":"cs.CR","authors_text":"Jianwei Yin, Qinfeng Li, Tianyu Du, Xinkui Zhao, Xuhong Zhang, Yucheng Zhang, Zhengwen Feng","submitted_at":"2024-10-30T09:15:51Z","abstract_excerpt":"Retrieval-Augmented Generation (RAG) systems enhance large language models (LLMs) by integrating external knowledge, making them adaptable and cost-effective for various applications. However, the growing reliance on these systems also introduces potential security risks. In this work, we reveal a novel vulnerability, the retrieval prompt hijack attack (HijackRAG), which enables attackers to manipulate the retrieval mechanisms of RAG systems by injecting malicious texts into the knowledge database. When the RAG system encounters target questions, it generates the attacker's pre-determined answ"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2410.22832","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2410.22832/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2410.22832","created_at":"2026-07-05T09:28:36.835643+00:00"},{"alias_kind":"arxiv_version","alias_value":"2410.22832v1","created_at":"2026-07-05T09:28:36.835643+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2410.22832","created_at":"2026-07-05T09:28:36.835643+00:00"},{"alias_kind":"pith_short_12","alias_value":"U4WGGRMJ5DLN","created_at":"2026-07-05T09:28:36.835643+00:00"},{"alias_kind":"pith_short_16","alias_value":"U4WGGRMJ5DLNG76F","created_at":"2026-07-05T09:28:36.835643+00:00"},{"alias_kind":"pith_short_8","alias_value":"U4WGGRMJ","created_at":"2026-07-05T09:28:36.835643+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":5,"internal_anchor_count":0,"sample":[{"citing_arxiv_id":"2606.01212","citing_title":"DiscourseFlip: An Oblique Discourse-Level Opinion Manipulation Attack against Black-box Retrieval-Augmented Generation","ref_index":46,"is_internal_anchor":false},{"citing_arxiv_id":"2606.28270","citing_title":"Agent-Native Immune System: Architecture, Taxonomy, and Engineering","ref_index":23,"is_internal_anchor":false},{"citing_arxiv_id":"2505.11548","citing_title":"One Shot Dominance: Knowledge Poisoning Attack on Retrieval-Augmented Generation Systems","ref_index":8,"is_internal_anchor":false},{"citing_arxiv_id":"2604.23338","citing_title":"A Systematic Survey of Security Threats and Defenses in LLM-Based AI Agents: A Layered Attack Surface Framework","ref_index":49,"is_internal_anchor":false},{"citing_arxiv_id":"2604.12201","citing_title":"AdversarialCoT: Single-Document Retrieval Poisoning for LLM Reasoning","ref_index":40,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/U4WGGRMJ5DLNG76F35XPH5BALZ","json":"https://pith.science/pith/U4WGGRMJ5DLNG76F35XPH5BALZ.json","graph_json":"https://pith.science/api/pith-number/U4WGGRMJ5DLNG76F35XPH5BALZ/graph.json","events_json":"https://pith.science/api/pith-number/U4WGGRMJ5DLNG76F35XPH5BALZ/events.json","paper":"https://pith.science/paper/U4WGGRMJ"},"agent_actions":{"view_html":"https://pith.science/pith/U4WGGRMJ5DLNG76F35XPH5BALZ","download_json":"https://pith.science/pith/U4WGGRMJ5DLNG76F35XPH5BALZ.json","view_paper":"https://pith.science/paper/U4WGGRMJ","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2410.22832&json=true","fetch_graph":"https://pith.science/api/pith-number/U4WGGRMJ5DLNG76F35XPH5BALZ/graph.json","fetch_events":"https://pith.science/api/pith-number/U4WGGRMJ5DLNG76F35XPH5BALZ/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/U4WGGRMJ5DLNG76F35XPH5BALZ/action/timestamp_anchor","attest_storage":"https://pith.science/pith/U4WGGRMJ5DLNG76F35XPH5BALZ/action/storage_attestation","attest_author":"https://pith.science/pith/U4WGGRMJ5DLNG76F35XPH5BALZ/action/author_attestation","sign_citation":"https://pith.science/pith/U4WGGRMJ5DLNG76F35XPH5BALZ/action/citation_signature","submit_replication":"https://pith.science/pith/U4WGGRMJ5DLNG76F35XPH5BALZ/action/replication_record"}},"created_at":"2026-07-05T09:28:36.835643+00:00","updated_at":"2026-07-05T09:28:36.835643+00:00"}