PoisonedRAG: Knowledge Corruption Attacks to Retrieval-Augmented Generation of Large Language Models
PoisonedRAG: атаки порчи знаний на генерацию с использованием извлечения для больших языковых моделей
2024-02-12
SCID: 54.1/rd9n2day
Discuss with AI
PoisonedRAGattack success rateknowledge corruption attackknowledge database poisoningretrieval-augmented generation
Figures from the paper
Abstract (AI)
Large language models (LLMs) have achieved remarkable success due to their exceptional generative capabilities. Despite their success, they also have inherent limitations such as a lack of up-to-date knowledge and hallucination. Retrieval-Augmented Generation (RAG) is a state-of-the-art technique to mitigate these limitations. The key idea of RAG is to ground the answer generation of an LLM on external knowledge retrieved from a knowledge database. Existing studies mainly focus on improving the accuracy or efficiency of RAG, leaving its security largely unexplored. We aim to bridge the gap in this work. We find that the knowledge database in a RAG system introduces a new and practical attack surface. Based on this attack surface, we propose PoisonedRAG, the first knowledge corruption attack to RAG, where an attacker could inject a few malicious texts into the knowledge database of a RAG system to induce an LLM to generate an attacker-chosen target answer for an attacker-chosen target question. We formulate knowledge corruption attacks as an optimization problem, whose solution is a set of malicious texts. Depending on the background knowledge (e.g., black-box and white-box settings) of an attacker on a RAG system, we propose two solutions to solve the optimization problem, respectively. Our results show PoisonedRAG could achieve a 90% attack success rate when injecting five malicious texts for each target question into a knowledge database with millions of texts. We also evaluate several defenses and our results show they are insufficient to defend against PoisonedRAG, highlighting the need for new defenses.
Key Findings
1
Evaluated existing defenses are insufficient to stop PoisonedRAG, indicating a need for new defense mechanisms for RAG systems.
2
PoisonedRAG achieves a 90% attack success rate when injecting five malicious texts per target question into a knowledge database containing millions of texts.
3
PoisonedRAG is the first proposed knowledge corruption attack that injects a few malicious texts into a RAG knowledge database to induce attacker-chosen answers for attacker-chosen questions.
4
Retrieval-Augmented Generation (RAG) systems introduce a practical attack surface via their knowledge database that can be exploited to corrupt generated answers.
5
The attack is formulated as an optimization problem whose solution yields the set of malicious texts; two solution methods are provided for different attacker knowledge settings (black-box and white-box).
Research Object
Retrieval-Augmented Generation (RAG) system's knowledge database and its interaction with a large language model
Research Subject
Knowledge corruption attacks (PoisonedRAG) that inject malicious texts into the RAG knowledge database to induce an LLM to generate attacker-chosen target answers, including attack formulation, optimization-based generation of malicious texts under black-box and white-box settings, attack success rates, and evaluation of defenses
Publication Details
Publication Date
2024-02-12
Journal
Publisher
ISSN
Cited by
12
Open access PDF
Access Type
Author Information
Download PDF
Subscribe to digest