🛰️ Daily AI Frontier
‹ back to 2026-09-21

Micro-Collaborative Poisoning: A Distributed Attack on RAG Systems

Research LLM Agents

Ranking

Overall 82
Content 100
Popularity 39

Observed public metrics from 1 member.

Representative image for Micro-Collaborative Poisoning: A Distributed Attack on RAG Systems

Merged summary

TL;DR - This paper introduces Micro-Collaborative Poisoning, a distributed attack that manipulates RAG outputs by spreading weak adversarial signals across multiple plausible documents. It matters because the attack can evade document-level inspection while gaining influence when poisoned sources are retrieved together.

  • Evaluated across 108 RAG configurations spanning datasets, retrievers, retrieval depths, database compositions, poisoning scope, and generator models.
  • Attack success arises from accumulated signals across documents rather than one dominant malicious passage.
  • Larger top-k retrieval and poisoning multiple databases increase the chance that adversarial evidence appears together.
  • Diverse clean databases and stronger retrievers can reduce the attack’s influence.

Sources (1)

Micro-Collaborative Poisoning: A Distributed Attack on RAG Systems

arXiv cs.CR Pedro Pereira, Eva Maia, Isabel Praça 2026-09-18 arXiv:2609.21573
Public signals Semantic Scholar citations 0 · Semantic Scholar influential citations 0
Providers: Hugging Face · N/A OpenAlex · N/A Publisher · N/A Semantic Scholar · Citations 0 · Influential citations 0 X · N/A Fetched 2026-09-24 14:16:54.035676 UTC

TL;DR - This paper introduces Micro-Collaborative Poisoning, a distributed attack that manipulates RAG outputs by spreading weak adversarial signals across multiple plausible documents. It matters because the attack can evade document-level inspection while gaining influence when poisoned sources are retrieved together.

  • Evaluated across 108 RAG configurations spanning datasets, retrievers, retrieval depths, database compositions, poisoning scope, and generator models.
  • Attack success arises from accumulated signals across documents rather than one dominant malicious passage.
  • Larger top-k retrieval and poisoning multiple databases increase the chance that adversarial evidence appears together.
  • Diverse clean databases and stronger retrievers can reduce the attack’s influence.
item →