|国家预印本平台
首页|Token-Level Precise Attack on RAG: Searching for the Best Alternatives to Mislead Generation

Token-Level Precise Attack on RAG: Searching for the Best Alternatives to Mislead Generation

Token-Level Precise Attack on RAG: Searching for the Best Alternatives to Mislead Generation

来源:Arxiv_logoArxiv
英文摘要

While large language models (LLMs) have achieved remarkable success in providing trustworthy responses for knowledge-intensive tasks, they still face critical limitations such as hallucinations and outdated knowledge. To address these issues, the retrieval-augmented generation (RAG) framework enhances LLMs with access to external knowledge via a retriever, enabling more accurate and real-time outputs about the latest events. However, this integration brings new security vulnerabilities: the risk that malicious content in the external database can be retrieved and used to manipulate model outputs. Although prior work has explored attacks on RAG systems, existing approaches either rely heavily on access to the retriever or fail to jointly consider both retrieval and generation stages, limiting their effectiveness, particularly in black-box scenarios. To overcome these limitations, we propose Token-level Precise Attack on the RAG (TPARAG), a novel framework that targets both white-box and black-box RAG systems. TPARAG leverages a lightweight white-box LLM as an attacker to generate and iteratively optimize malicious passages at the token level, ensuring both retrievability and high attack success in generation. Extensive experiments on open-domain QA datasets demonstrate that TPARAG consistently outperforms previous approaches in retrieval-stage and end-to-end attack effectiveness. These results further reveal critical vulnerabilities in RAG pipelines and offer new insights into improving their robustness.

Zizhong Li、Haopeng Zhang、Jiawei Zhang

信息传播、知识传播计算技术、计算机技术

Zizhong Li,Haopeng Zhang,Jiawei Zhang.Token-Level Precise Attack on RAG: Searching for the Best Alternatives to Mislead Generation[EB/OL].(2025-08-05)[2025-08-24].https://arxiv.org/abs/2508.03110.点此复制

评论