paper

Adversarial Threat Vectors and Risk Mitigation for Retrieval-Augmented Generation Systems

arXiv:2506.00281 · doi:10.1117/12.3055931

Abstract

Retrieval-Augmented Generation (RAG) systems, which integrate Large Language Models (LLMs) with external knowledge sources, are vulnerable to a range of adversarial attack vectors. This paper examines the importance of RAG systems through recent industry adoption trends and identifies the prominent attack vectors for RAG: prompt injection, data poisoning, and adversarial query manipulation. We analyze these threats under risk management lens, and propose robust prioritized control list that includes risk-mitigating actions like input validation, adversarial training, and real-time monitoring.

SPIE DCS: Proceedings Volume Assurance and Security for AI-enabled Systems 2025

Adversarial Threat Vectors and Risk Mitigation for Retrieval-Augmented Generation Systems · wovepaper