恶意客户端伪造语义信息,劫持联邦检索生成中的路由决策。
A Wolf in Sheep's Clothing: Targeted Routing Hijacking in Federated RAG

- 通过伪造语义档案,让无关数据的客户端诱骗目标查询
- 三种路由架构均出现误分流,导致答案错误、幻觉和证据污染
- 适合关注联邦学习安全与检索系统鲁棒性的研究者
联邦检索增强生成(FedRAG)因其本地数据不外泄而适用于隐私敏感场景,但路由依赖客户端提供的语义档案,带来新攻击面。本文提出路由劫持攻击:恶意客户端伪造档案,吸引目标查询,即使其数据无关。在三种典型路由架构中,该攻击持续误导查询,引发下游失效,包括证据缺失、数据污染、错误回答与幻觉。在受控的MedQA-USMLE压力测试中,污染的检索证据可误导多规模模型,导致错误答案、幻觉及谄媚性失败。现有防御无效:加密路由仍暴露排名机制,拜占庭鲁棒联邦学习规则难以适配异构路由档案。为此,我们提出信任感知后路由框架,基于返回证据反馈(检索相关性、档案一致性、跨客户端共识)重新加权客户端;在线实验表明,该框架能抑制重复查询的持续劫持,并迁移至神经路由模型。研究揭示路由完整性是FedRAG的关键安全挑战,亟需更强防御机制。
原文摘要 · Abstract (English)
Federated Retrieval-Augmented Generation (FedRAG) is attractive for privacy-sensitive applications because full local corpora remain on clients. As a result, routing must rely on client-provided semantic profiles, creating a new opportunity for manipulation. We introduce Routing Hijacking, a routing-stage attack in which a malicious client forges its profile to attract target queries despite having irrelevant underlying data. We show that this vulnerability is severe. Across three representative FedRAG routing architectures, Routing Hijacking consistently misroutes target queries and leads to downstream disruptions and failures, including missing evidence, poisoning, incorrect answers, and hallucinations. In a controlled MedQA-USMLE stress test, we further show that poisoned retrieved evidence can mislead models across scales, leading to incorrect answers, hallucinations, and sycophantic failures. Existing defenses do not close this gap: encrypted routing preserves the exploited ranking, and Byzantine-robust Federated Learning (FL) rules transfer poorly to heterogeneous routing profiles. To address this gap, we propose a trust-aware post-routing framework that reweights clients using returned-evidence feedback, including retrieval relevance, profile consistency, and cross-client agreement; online experiments show that it suppresses persistent hijacking over recurring queries and transfers to a learned neural router. Our findings establish routing integrity as a security challenge in FedRAG and highlight the need for stronger defenses for secure federated retrieval.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。