{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2024:X4P3WV5SBRQCUJWJCU6D2GKC3T","short_pith_number":"pith:X4P3WV5S","schema_version":"1.0","canonical_sha256":"bf1fbb57b20c602a26c9153c3d1942dce199b60b793d7866e13e2b9c24cad140","source":{"kind":"arxiv","id":"2409.08045","version":1},"attestation_state":"computed","paper":{"title":"Unleashing Worms and Extracting Data: Escalating the Outcome of Attacks against RAG-based Inference in Scale and Severity Using Jailbreaking","license":"http://creativecommons.org/licenses/by-nc-nd/4.0/","headline":"","cross_cats":["cs.AI"],"primary_cat":"cs.CR","authors_text":"Ben Nassi, Ron Bitton, Stav Cohen","submitted_at":"2024-09-12T13:50:22Z","abstract_excerpt":"In this paper, we show that with the ability to jailbreak a GenAI model, attackers can escalate the outcome of attacks against RAG-based GenAI-powered applications in severity and scale. In the first part of the paper, we show that attackers can escalate RAG membership inference attacks and RAG entity extraction attacks to RAG documents extraction attacks, forcing a more severe outcome compared to existing attacks. We evaluate the results obtained from three extraction methods, the influence of the type and the size of five embeddings algorithms employed, the size of the provided context, and "},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2409.08045","kind":"arxiv","version":1},"metadata":{"license":"http://creativecommons.org/licenses/by-nc-nd/4.0/","primary_cat":"cs.CR","submitted_at":"2024-09-12T13:50:22Z","cross_cats_sorted":["cs.AI"],"title_canon_sha256":"3d013d5493ab37da8a62e7892ad83f20018b57985f014e4baa1c23704812d6a8","abstract_canon_sha256":"94d2c9df4afadbc2ead1858733a0d32d757d83a9ff3a23b5588bdc92d3225244"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T10:07:01.729121Z","signature_b64":"7mUJae6HRooaZh3Nfhcd8A+6qZzBXyp0PfzZ25solv417gr0dBhfTxNG6CeeBjgWtzgumZu1+Qd0V/ZY7CtrCQ==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"bf1fbb57b20c602a26c9153c3d1942dce199b60b793d7866e13e2b9c24cad140","last_reissued_at":"2026-07-05T10:07:01.728686Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T10:07:01.728686Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Unleashing Worms and Extracting Data: Escalating the Outcome of Attacks against RAG-based Inference in Scale and Severity Using Jailbreaking","license":"http://creativecommons.org/licenses/by-nc-nd/4.0/","headline":"","cross_cats":["cs.AI"],"primary_cat":"cs.CR","authors_text":"Ben Nassi, Ron Bitton, Stav Cohen","submitted_at":"2024-09-12T13:50:22Z","abstract_excerpt":"In this paper, we show that with the ability to jailbreak a GenAI model, attackers can escalate the outcome of attacks against RAG-based GenAI-powered applications in severity and scale. In the first part of the paper, we show that attackers can escalate RAG membership inference attacks and RAG entity extraction attacks to RAG documents extraction attacks, forcing a more severe outcome compared to existing attacks. We evaluate the results obtained from three extraction methods, the influence of the type and the size of five embeddings algorithms employed, the size of the provided context, and "},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2409.08045","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2409.08045/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2409.08045","created_at":"2026-07-05T10:07:01.728751+00:00"},{"alias_kind":"arxiv_version","alias_value":"2409.08045v1","created_at":"2026-07-05T10:07:01.728751+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2409.08045","created_at":"2026-07-05T10:07:01.728751+00:00"},{"alias_kind":"pith_short_12","alias_value":"X4P3WV5SBRQC","created_at":"2026-07-05T10:07:01.728751+00:00"},{"alias_kind":"pith_short_16","alias_value":"X4P3WV5SBRQCUJWJ","created_at":"2026-07-05T10:07:01.728751+00:00"},{"alias_kind":"pith_short_8","alias_value":"X4P3WV5S","created_at":"2026-07-05T10:07:01.728751+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":5,"internal_anchor_count":0,"sample":[{"citing_arxiv_id":"2606.24623","citing_title":"Privacy-Preserving RAG via Multi-Agent Semantic Rewriting: Achieving Confidentiality Without Compromising Contextual Fidelity","ref_index":3,"is_internal_anchor":false},{"citing_arxiv_id":"2605.18762","citing_title":"ALDEN: Boosting Private Data Extraction from Retrieval-Augmented Generation Systems via Active Learning and Distribution Estimation","ref_index":12,"is_internal_anchor":false},{"citing_arxiv_id":"2604.10717","citing_title":"Detecting RAG Extraction Attack via Dual-Path Runtime Integrity Game","ref_index":2,"is_internal_anchor":false},{"citing_arxiv_id":"2604.09747","citing_title":"ADAM: A Systematic Data Extraction Attack on Agent Memory via Adaptive Querying","ref_index":3,"is_internal_anchor":false},{"citing_arxiv_id":"2604.15958","citing_title":"A Case Study on the Impact of Anonymization Along the RAG Pipeline","ref_index":4,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/X4P3WV5SBRQCUJWJCU6D2GKC3T","json":"https://pith.science/pith/X4P3WV5SBRQCUJWJCU6D2GKC3T.json","graph_json":"https://pith.science/api/pith-number/X4P3WV5SBRQCUJWJCU6D2GKC3T/graph.json","events_json":"https://pith.science/api/pith-number/X4P3WV5SBRQCUJWJCU6D2GKC3T/events.json","paper":"https://pith.science/paper/X4P3WV5S"},"agent_actions":{"view_html":"https://pith.science/pith/X4P3WV5SBRQCUJWJCU6D2GKC3T","download_json":"https://pith.science/pith/X4P3WV5SBRQCUJWJCU6D2GKC3T.json","view_paper":"https://pith.science/paper/X4P3WV5S","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2409.08045&json=true","fetch_graph":"https://pith.science/api/pith-number/X4P3WV5SBRQCUJWJCU6D2GKC3T/graph.json","fetch_events":"https://pith.science/api/pith-number/X4P3WV5SBRQCUJWJCU6D2GKC3T/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/X4P3WV5SBRQCUJWJCU6D2GKC3T/action/timestamp_anchor","attest_storage":"https://pith.science/pith/X4P3WV5SBRQCUJWJCU6D2GKC3T/action/storage_attestation","attest_author":"https://pith.science/pith/X4P3WV5SBRQCUJWJCU6D2GKC3T/action/author_attestation","sign_citation":"https://pith.science/pith/X4P3WV5SBRQCUJWJCU6D2GKC3T/action/citation_signature","submit_replication":"https://pith.science/pith/X4P3WV5SBRQCUJWJCU6D2GKC3T/action/replication_record"}},"created_at":"2026-07-05T10:07:01.728751+00:00","updated_at":"2026-07-05T10:07:01.728751+00:00"}