Pith. sign in

REVIEW 3 cited by

Uncovering Competing Poisoning Attacks in Retrieval-Augmented Generation

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2505.12574 v5 pith:TAIUDABD submitted 2025-05-18 cs.IR

classification cs.IR
keywords underattackspoisoningadversariescompetingcompetitiongenerationmultiple
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

Retrieval-Augmented Generation (RAG) systems improve the factual grounding of large language models (LLMs) but remain vulnerable to retrieval poisoning, where adversaries seed the corpus with manipulated content. Prior work largely evaluates this threat under a simplified single-attacker assumption. In practice, however, high-value or high-visibility queries attract multiple adversaries with conflicting objectives. Motivated by real cases, we introduce the setting of competing attacks, in which multiple attackers simultaneously attempt to steer the same or closely related query toward different targets. We formalize this threat model and propose competitive effectiveness, a metric that quantifies an attacker's advantage under competition. Extensive experiments show that many strategies that succeed in the single-attacker regime degrade markedly under competition, revealing performance inversions and highlighting the limits of conventional metrics such as attack success rate and F1. Furthermore, we present PoisonArena, a standardized framework and benchmark for evaluating poisoning attacks and defenses under realistic, multi-adversary conditions.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 3 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. A Failure-Mode Benchmark for Polymorphic Sybil Poisoning in RAG

    cs.CR 2026-07 conditional novelty 6.5 of 10

    Polymorphic sybil groups of six diverse passages amplify hijack rates 5.7× over monomorphic copies under Forced Exposure and leave 47–66% of outputs in unmonitored abstention or drift.

  2. EviSD: Evidence-Conditioned Self-Distillation for Search-Augmented Agents

    cs.CL 2026-08 conditional novelty 6.0 of 10

    EviSD improves search-agent RL by re-scoring each sampled action under a context containing supporting evidence or the golden answer, and using that detached gap to modulate GRPO credit only on action tokens.

  3. Large Language Models in Misinformation Ecosystems: Misuse, Defense, and Vulnerability

    cs.CR 2026-07 conditional novelty 5.0 of 10

    A role-layer survey unifies LLM misuse, LLM-based defense, and LLM-centric verification vulnerabilities across content, social, evidence, and workflow layers, then lists three open challenges.

Pith tools