Conflict-Aware Retriever Editing for Knowledge Injection Attacks on LLM-Based RAG Systems
2026-06-18T07:23:30Z•91465eaccf21be5bf46ccd1e0621b79408f4459f11695873c21419b8974c62f3
AgentraCAREATTACKGDPRHIPAAHNSWPII-exposureRAGSafeClawBenchTIGERVec2Textauditabilitydata-recoverydifferential-privacyembedding-inversionepoch-key-rotationfederated-learninggradient-inversionintrusion-response','IRSmemory-poisoningmodel-centric-attackprompt-injectionretriever-editingsoft-deletetool-using-agentsvector-database
What happened
A set of June 18, 2026 security/ML papers exposing multiple high-risk attack surfaces and measurement artifacts. Key findings: CAREATTACK demonstrates a practical model-centric retriever-editing attack that promotes malicious passages into RAG retrievals by editing open-source dense retrievers and using conflict detection plus anchor repair; TIGER is a new, more robust gradient-inversion attack that reconstructs client inputs from transformer gradients — including in some DP settings; Ghost Vectors shows soft-deleted embeddings in HNSW vector databases remain recoverable from index files, with
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- arxiv_cs_cr
- Record identifier
- 91465eaccf21be5bf46ccd1e0621b79408f4459f11695873c21419b8974c62f3
- Enrichment time
- 2026-06-18T07:23:30Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.