Conflict-Aware Retriever Editing for Knowledge Injection Attacks on LLM-Based RAG Systems

2026-06-18T07:23:30Z91465eaccf21be5bf46ccd1e0621b79408f4459f11695873c21419b8974c62f3
AgentraCAREATTACKGDPRHIPAAHNSWPII-exposureRAGSafeClawBenchTIGERVec2Textauditabilitydata-recoverydifferential-privacyembedding-inversionepoch-key-rotationfederated-learninggradient-inversionintrusion-response','IRSmemory-poisoningmodel-centric-attackprompt-injectionretriever-editingsoft-deletetool-using-agentsvector-database

What happened

A set of June 18, 2026 security/ML papers exposing multiple high-risk attack surfaces and measurement artifacts. Key findings: CAREATTACK demonstrates a practical model-centric retriever-editing attack that promotes malicious passages into RAG retrievals by editing open-source dense retrievers and using conflict detection plus anchor repair; TIGER is a new, more robust gradient-inversion attack that reconstructs client inputs from transformer gradients — including in some DP settings; Ghost Vectors shows soft-deleted embeddings in HNSW vector databases remain recoverable from index files, with

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
arxiv_cs_cr
Record identifier
91465eaccf21be5bf46ccd1e0621b79408f4459f11695873c21419b8974c62f3
Enrichment time
2026-06-18T07:23:30Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.