Skip to content
Rota Nacional

Radar ·

HijackRAG explores injected text attacks on RAG systems

Published on December 1, 2024, the post presents HijackRAG, an attack that manipulates RAG systems through retrieved content, attention diversion, and instructions.

Published on December 1, 2024, the post describes HijackRAG, an attack combining retrieved texts, attention diversion, and instructions to manipulate RAG system outputs. According to the summary, it presents black-box and white-box modes using gradient-based optimization.

The post highlights risks from malicious content in RAG knowledge bases and limits in existing defenses. Consult the original publication to verify its methods and findings; the material available here provides no additional metrics or experimental details. Organizations using AI to study or apply these ideas should avoid submitting sensitive data without authorization.

Get new articles

Privacy, AI engineering and security in your inbox.

Rota Nacional

Bring privacy into your workflow.

30 days, no card, with a starting quota. After that, Pix credit from R$ 5,00.

Try free