arXiv:2506.00281cs.CRcs.AI2025-06被引 8

揭示RAG系统三大攻击风险并提出防护清单

Adversarial Threat Vectors and Risk Mitigation for Retrieval-Augmented Generation Systems

  • 从提示注入、数据污染等角度分析RAG安全威胁
  • 提出包含输入验证等三类控制措施的优先级清单
  • 适合关注大模型应用安全的工程师与研究者

检索增强生成(RAG)系统通过整合大型语言模型(LLMs)与外部知识源,在工业界广泛应用。然而,这类系统面临多种对抗性攻击风险。本文基于近期行业采用趋势,识别出三大主要攻击向量:提示注入、数据污染和对抗性查询操纵。我们从风险管理视角分析这些威胁,并提出一套优先级明确的鲁棒控制清单,包括输入验证、对抗训练和实时监控等风险缓解措施。

原文摘要 · Abstract (English)

Retrieval-Augmented Generation (RAG) systems, which integrate Large Language Models (LLMs) with external knowledge sources, are vulnerable to a range of adversarial attack vectors. This paper examines the importance of RAG systems through recent industry adoption trends and identifies the prominent attack vectors for RAG: prompt injection, data poisoning, and adversarial query manipulation. We analyze these threats under risk management lens, and propose robust prioritized control list that includes risk-mitigating actions like input validation, adversarial training, and real-time monitoring.

RAG安全对抗攻击大模型防御

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。