{"id":"https://openalex.org/W7124134671","doi":"https://doi.org/10.1109/icpads67057.2025.11322925","title":"AutoTPA: Automated and Efficient Trigger-Targeted Data Poisoning in Retrieval-Augmented Generation","display_name":"AutoTPA: Automated and Efficient Trigger-Targeted Data Poisoning in Retrieval-Augmented Generation","publication_year":2025,"publication_date":"2025-12-14","ids":{"openalex":"https://openalex.org/W7124134671","doi":"https://doi.org/10.1109/icpads67057.2025.11322925"},"language":null,"primary_location":{"id":"doi:10.1109/icpads67057.2025.11322925","is_oa":false,"landing_page_url":"https://doi.org/10.1109/icpads67057.2025.11322925","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2025 IEEE 31th International Conference on Parallel and Distributed Systems (ICPADS)","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5025271419","display_name":"Chenhao Jin","orcid":null},"institutions":[{"id":"https://openalex.org/I183067930","display_name":"Shanghai Jiao Tong University","ror":"https://ror.org/0220qvk04","country_code":"CN","type":"education","lineage":["https://openalex.org/I183067930"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Chenhao Jin","raw_affiliation_strings":["School of Computer Science, Shanghai Jiao Tong University,Shanghai,China"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"School of Computer Science, Shanghai Jiao Tong University,Shanghai,China","institution_ids":["https://openalex.org/I183067930"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5012838964","display_name":"Jian Ma","orcid":"https://orcid.org/0000-0001-9072-6099"},"institutions":[{"id":"https://openalex.org/I183067930","display_name":"Shanghai Jiao Tong University","ror":"https://ror.org/0220qvk04","country_code":"CN","type":"education","lineage":["https://openalex.org/I183067930"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Jin Ma","raw_affiliation_strings":["School of Computer Science, Shanghai Jiao Tong University,Shanghai,China"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"School of Computer Science, Shanghai Jiao Tong University,Shanghai,China","institution_ids":["https://openalex.org/I183067930"]}]},{"author_position":"middle","author":{"id":null,"display_name":"Xiuzhen Chen","orcid":null},"institutions":[{"id":"https://openalex.org/I183067930","display_name":"Shanghai Jiao Tong University","ror":"https://ror.org/0220qvk04","country_code":"CN","type":"education","lineage":["https://openalex.org/I183067930"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Xiuzhen Chen","raw_affiliation_strings":["School of Computer Science, Shanghai Jiao Tong University,Shanghai,China"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"School of Computer Science, Shanghai Jiao Tong University,Shanghai,China","institution_ids":["https://openalex.org/I183067930"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5083464383","display_name":"Yinghua Ma","orcid":"https://orcid.org/0000-0003-1852-1093"},"institutions":[{"id":"https://openalex.org/I183067930","display_name":"Shanghai Jiao Tong University","ror":"https://ror.org/0220qvk04","country_code":"CN","type":"education","lineage":["https://openalex.org/I183067930"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Yinghua Ma","raw_affiliation_strings":["School of Computer Science, Shanghai Jiao Tong University,Shanghai,China"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"School of Computer Science, Shanghai Jiao Tong University,Shanghai,China","institution_ids":["https://openalex.org/I183067930"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5123001785","display_name":"Zhihong Zhou","orcid":null},"institutions":[{"id":"https://openalex.org/I183067930","display_name":"Shanghai Jiao Tong University","ror":"https://ror.org/0220qvk04","country_code":"CN","type":"education","lineage":["https://openalex.org/I183067930"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Zhihong Zhou","raw_affiliation_strings":["School of Computer Science, Shanghai Jiao Tong University,Shanghai,China"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"School of Computer Science, Shanghai Jiao Tong University,Shanghai,China","institution_ids":["https://openalex.org/I183067930"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":5,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":0.0,"has_fulltext":false,"cited_by_count":0,"citation_normalized_percentile":{"value":0.79439905,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":null,"biblio":{"volume":null,"issue":null,"first_page":"1","last_page":"4"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10028","display_name":"Topic Modeling","score":0.34850001335144043,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10028","display_name":"Topic Modeling","score":0.34850001335144043,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11273","display_name":"Advanced Graph Neural Networks","score":0.18310000002384186,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10181","display_name":"Natural Language Processing Techniques","score":0.06350000202655792,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/reliability","display_name":"Reliability (semiconductor)","score":0.6158000230789185},{"id":"https://openalex.org/keywords/set","display_name":"Set (abstract data type)","score":0.6111000180244446},{"id":"https://openalex.org/keywords/heuristic","display_name":"Heuristic","score":0.5978999733924866},{"id":"https://openalex.org/keywords/inefficiency","display_name":"Inefficiency","score":0.5974000096321106},{"id":"https://openalex.org/keywords/security-token","display_name":"Security token","score":0.5914999842643738},{"id":"https://openalex.org/keywords/generalization","display_name":"Generalization","score":0.5271999835968018},{"id":"https://openalex.org/keywords/data-set","display_name":"Data set","score":0.35269999504089355}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7738000154495239},{"id":"https://openalex.org/C43214815","wikidata":"https://www.wikidata.org/wiki/Q7310987","display_name":"Reliability (semiconductor)","level":3,"score":0.6158000230789185},{"id":"https://openalex.org/C177264268","wikidata":"https://www.wikidata.org/wiki/Q1514741","display_name":"Set (abstract data type)","level":2,"score":0.6111000180244446},{"id":"https://openalex.org/C173801870","wikidata":"https://www.wikidata.org/wiki/Q201413","display_name":"Heuristic","level":2,"score":0.5978999733924866},{"id":"https://openalex.org/C2778869765","wikidata":"https://www.wikidata.org/wiki/Q6028363","display_name":"Inefficiency","level":2,"score":0.5974000096321106},{"id":"https://openalex.org/C48145219","wikidata":"https://www.wikidata.org/wiki/Q1335365","display_name":"Security token","level":2,"score":0.5914999842643738},{"id":"https://openalex.org/C177148314","wikidata":"https://www.wikidata.org/wiki/Q170084","display_name":"Generalization","level":2,"score":0.5271999835968018},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.3716000020503998},{"id":"https://openalex.org/C58489278","wikidata":"https://www.wikidata.org/wiki/Q1172284","display_name":"Data set","level":2,"score":0.35269999504089355},{"id":"https://openalex.org/C124101348","wikidata":"https://www.wikidata.org/wiki/Q172491","display_name":"Data mining","level":1,"score":0.34279999136924744},{"id":"https://openalex.org/C95713431","wikidata":"https://www.wikidata.org/wiki/Q631425","display_name":"Vulnerability (computing)","level":2,"score":0.3262999951839447},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.2946000099182129},{"id":"https://openalex.org/C5655090","wikidata":"https://www.wikidata.org/wiki/Q192588","display_name":"Relational database","level":2,"score":0.2892000079154968},{"id":"https://openalex.org/C51632099","wikidata":"https://www.wikidata.org/wiki/Q3985153","display_name":"Training set","level":2,"score":0.28519999980926514},{"id":"https://openalex.org/C51823790","wikidata":"https://www.wikidata.org/wiki/Q504353","display_name":"Greedy algorithm","level":2,"score":0.2799000144004822},{"id":"https://openalex.org/C67186912","wikidata":"https://www.wikidata.org/wiki/Q367664","display_name":"Data modeling","level":2,"score":0.2777999937534332},{"id":"https://openalex.org/C152124472","wikidata":"https://www.wikidata.org/wiki/Q1204361","display_name":"Redundancy (engineering)","level":2,"score":0.26100000739097595}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1109/icpads67057.2025.11322925","is_oa":false,"landing_page_url":"https://doi.org/10.1109/icpads67057.2025.11322925","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2025 IEEE 31th International Conference on Parallel and Distributed Systems (ICPADS)","raw_type":"proceedings-article"}],"best_oa_location":null,"sustainable_development_goals":[{"score":0.6994928121566772,"id":"https://metadata.un.org/sdg/4","display_name":"Quality Education"}],"awards":[],"funders":[],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":5,"referenced_works":["https://openalex.org/W4389519591","https://openalex.org/W4404534210","https://openalex.org/W4404781805","https://openalex.org/W4416034285","https://openalex.org/W4416354085"],"related_works":[],"abstract_inverted_index":{"By":[0],"synergizing":[1],"external":[2,36],"knowledge":[3,37],"with":[4,69],"generative":[5],"capabilities,":[6],"RAG":[7,39,98],"is":[8,79,144],"emerging":[9],"as":[10,122,124],"an":[11,158],"important":[12],"approach":[13],"for":[14,53],"enhancing":[15],"the":[16,28,33,107,139,147,181],"professionalism":[17],"and":[18,116,131,195],"reliability":[19,34],"of":[20,30,35,134,180],"Large":[21],"Language":[22],"Models":[23],"(LLMs).":[24],"However,":[25],"due":[26],"to":[27,43,74,142,145,149,163],"difficulty":[29],"fully":[31],"ensuring":[32],"sources,":[38],"systems":[40],"are":[41,50],"vulnerable":[42],"data":[44],"poisoning":[45,48,99],"attacks.":[46],"Existing":[47],"attacks":[49],"typically":[51],"designed":[52],"a":[54,96,172],"single":[55],"specific":[56,108],"query,":[57],"exhibiting":[58],"limited":[59,75],"generalization":[60],"capability.":[61],"In":[62,90],"addition,":[63],"existing":[64,187],"methods":[65],"craft":[66],"poisoned":[67,87,136],"texts":[68],"low":[70],"retrieval":[71],"probability,":[72],"leading":[73],"attack":[76,159],"effectiveness.":[77,196],"What":[78],"more,":[80],"they":[81],"also":[82],"suffer":[83],"from":[84],"inefficiency":[85],"in":[86,166,192],"text":[88],"construction.":[89],"this":[91],"paper,":[92],"we":[93],"propose":[94],"AutoTPA,":[95],"novel":[97],"attack,":[100],"which":[101],"targets":[102],"all":[103],"user":[104],"queries":[105],"containing":[106],"trigger.":[109],"AutoTPA":[110,156],"integrates":[111],"dynamic":[112],"query":[113],"clustering,":[114],"efficient":[115,132],"minimal":[117],"candidate":[118],"token":[119,126,173],"set":[120,174],"construction,":[121],"well":[123],"heuristic":[125],"evaluation":[127],"algorithm,":[128],"enabling":[129],"automated":[130],"construction":[133],"effective":[135],"texts.":[137],"All":[138],"attacker":[140],"has":[141],"do":[143],"determine":[146],"trigger":[148],"attack.":[150],"Extensive":[151],"experimental":[152],"results":[153],"demonstrate":[154],"that":[155],"achieves":[157],"success":[160],"rate":[161],"up":[162],"95.5":[164],"%":[165,179],"less":[167],"time":[168],"while":[169],"using":[170],"only":[171],"sized":[175],"at":[176],"about":[177],"3.5":[178],"original":[182],"vocabulary.":[183],"It":[184],"significantly":[185],"outperforms":[186],"methods,":[188],"showing":[189],"clear":[190],"advantages":[191],"both":[193],"efficiency":[194]},"counts_by_year":[],"updated_date":"2026-06-11T09:08:48.828518","created_date":"2026-01-15T00:00:00"}
