{"id":"https://openalex.org/W4409657545","doi":"https://doi.org/10.1145/3696410.3714756","title":"Traceback of Poisoning Attacks to Retrieval-Augmented Generation","display_name":"Traceback of Poisoning Attacks to Retrieval-Augmented Generation","publication_year":2025,"publication_date":"2025-04-22","ids":{"openalex":"https://openalex.org/W4409657545","doi":"https://doi.org/10.1145/3696410.3714756"},"language":"en","primary_location":{"id":"doi:10.1145/3696410.3714756","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3696410.3714756","pdf_url":"https://dl.acm.org/doi/pdf/10.1145/3696410.3714756","source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the ACM on Web Conference 2025","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":true,"oa_status":"gold","oa_url":"https://dl.acm.org/doi/pdf/10.1145/3696410.3714756","any_repository_has_fulltext":null},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5034371700","display_name":"Baolei Zhang","orcid":"https://orcid.org/0000-0002-1807-5946"},"institutions":[{"id":"https://openalex.org/I205237279","display_name":"Nankai University","ror":"https://ror.org/01y1kjr75","country_code":"CN","type":"education","lineage":["https://openalex.org/I205237279"]}],"countries":["CN"],"is_corresponding":true,"raw_author_name":"Baolei Zhang","raw_affiliation_strings":["CCS&amp;CS, DISSec, Nankai University, Tianjin, China"],"affiliations":[{"raw_affiliation_string":"CCS&amp;CS, DISSec, Nankai University, Tianjin, China","institution_ids":["https://openalex.org/I205237279"]}]},{"author_position":"middle","author":{"id":null,"display_name":"Haoran Xin","orcid":"https://orcid.org/0009-0001-7290-1583"},"institutions":[{"id":"https://openalex.org/I205237279","display_name":"Nankai University","ror":"https://ror.org/01y1kjr75","country_code":"CN","type":"education","lineage":["https://openalex.org/I205237279"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Haoran Xin","raw_affiliation_strings":["CCS&amp;CS, DISSec, Nankai University, Tianjin, China"],"affiliations":[{"raw_affiliation_string":"CCS&amp;CS, DISSec, Nankai University, Tianjin, China","institution_ids":["https://openalex.org/I205237279"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5056811906","display_name":"Minghong Fang","orcid":"https://orcid.org/0000-0002-1365-3911"},"institutions":[{"id":"https://openalex.org/I142740786","display_name":"University of Louisville","ror":"https://ror.org/01ckdn478","country_code":"US","type":"education","lineage":["https://openalex.org/I142740786"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Minghong Fang","raw_affiliation_strings":["University of Louisville, Louisville, USA"],"affiliations":[{"raw_affiliation_string":"University of Louisville, Louisville, USA","institution_ids":["https://openalex.org/I142740786"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5086560839","display_name":"Zhuqing Liu","orcid":"https://orcid.org/0000-0003-0146-5101"},"institutions":[{"id":"https://openalex.org/I123534392","display_name":"University of North Texas","ror":"https://ror.org/00v97ad02","country_code":"US","type":"education","lineage":["https://openalex.org/I123534392"]},{"id":"https://openalex.org/I205237279","display_name":"Nankai University","ror":"https://ror.org/01y1kjr75","country_code":"CN","type":"education","lineage":["https://openalex.org/I205237279"]}],"countries":["CN","US"],"is_corresponding":false,"raw_author_name":"Zhuqing Liu","raw_affiliation_strings":["CCS&amp;CS, DISSec, Nankai University, Tianjin, China","University of North Texas, Denton, USA"],"affiliations":[{"raw_affiliation_string":"CCS&amp;CS, DISSec, Nankai University, Tianjin, China","institution_ids":["https://openalex.org/I205237279"]},{"raw_affiliation_string":"University of North Texas, Denton, USA","institution_ids":["https://openalex.org/I123534392"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5043264924","display_name":"Biao Yi","orcid":"https://orcid.org/0000-0002-8347-1953"},"institutions":[{"id":"https://openalex.org/I205237279","display_name":"Nankai University","ror":"https://ror.org/01y1kjr75","country_code":"CN","type":"education","lineage":["https://openalex.org/I205237279"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Biao Yi","raw_affiliation_strings":["CCS&amp;CS, DISSec, Nankai University, Tianjin, China"],"affiliations":[{"raw_affiliation_string":"CCS&amp;CS, DISSec, Nankai University, Tianjin, China","institution_ids":["https://openalex.org/I205237279"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5100359059","display_name":"Tong Li","orcid":"https://orcid.org/0000-0003-3678-8402"},"institutions":[{"id":"https://openalex.org/I205237279","display_name":"Nankai University","ror":"https://ror.org/01y1kjr75","country_code":"CN","type":"education","lineage":["https://openalex.org/I205237279"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Tong Li","raw_affiliation_strings":["CCS&amp;CS, DISSec, Nankai University, Tianjin, China"],"affiliations":[{"raw_affiliation_string":"CCS&amp;CS, DISSec, Nankai University, Tianjin, China","institution_ids":["https://openalex.org/I205237279"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5060212061","display_name":"Zheli Liu","orcid":"https://orcid.org/0000-0002-2984-2661"},"institutions":[{"id":"https://openalex.org/I123534392","display_name":"University of North Texas","ror":"https://ror.org/00v97ad02","country_code":"US","type":"education","lineage":["https://openalex.org/I123534392"]},{"id":"https://openalex.org/I205237279","display_name":"Nankai University","ror":"https://ror.org/01y1kjr75","country_code":"CN","type":"education","lineage":["https://openalex.org/I205237279"]}],"countries":["CN","US"],"is_corresponding":false,"raw_author_name":"Zheli Liu","raw_affiliation_strings":["CCS&amp;CS, DISSec, Nankai University, Tianjin, China","University of North Texas, Denton, USA"],"affiliations":[{"raw_affiliation_string":"CCS&amp;CS, DISSec, Nankai University, Tianjin, China","institution_ids":["https://openalex.org/I205237279"]},{"raw_affiliation_string":"University of North Texas, Denton, USA","institution_ids":["https://openalex.org/I123534392"]}]}],"institutions":[],"countries_distinct_count":2,"institutions_distinct_count":7,"corresponding_author_ids":["https://openalex.org/A5034371700"],"corresponding_institution_ids":["https://openalex.org/I205237279"],"apc_list":null,"apc_paid":null,"fwci":5.6296,"has_fulltext":true,"cited_by_count":4,"citation_normalized_percentile":{"value":0.95586575,"is_in_top_1_percent":false,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":95,"max":99},"biblio":{"volume":null,"issue":null,"first_page":"2085","last_page":"2097"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.9968000054359436,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.9968000054359436,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11598","display_name":"Internet Traffic Analysis and Secure E-voting","score":0.989300012588501,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10028","display_name":"Topic Modeling","score":0.9886999726295471,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.6784707307815552},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.460126131772995}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.6784707307815552},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.460126131772995}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1145/3696410.3714756","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3696410.3714756","pdf_url":"https://dl.acm.org/doi/pdf/10.1145/3696410.3714756","source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the ACM on Web Conference 2025","raw_type":"proceedings-article"}],"best_oa_location":{"id":"doi:10.1145/3696410.3714756","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3696410.3714756","pdf_url":"https://dl.acm.org/doi/pdf/10.1145/3696410.3714756","source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the ACM on Web Conference 2025","raw_type":"proceedings-article"},"sustainable_development_goals":[],"awards":[{"id":"https://openalex.org/G1121271761","display_name":null,"funder_award_id":"Program","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"},{"id":"https://openalex.org/G2087396116","display_name":null,"funder_award_id":"China","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"},{"id":"https://openalex.org/G3317480652","display_name":null,"funder_award_id":"Science","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"},{"id":"https://openalex.org/G4856742107","display_name":null,"funder_award_id":"62302242","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"},{"id":"https://openalex.org/G4940997820","display_name":null,"funder_award_id":"62272251","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"},{"id":"https://openalex.org/G5994120800","display_name":null,"funder_award_id":"Natural","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"},{"id":"https://openalex.org/G6058138561","display_name":null,"funder_award_id":", No.","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"},{"id":"https://openalex.org/G6330607538","display_name":null,"funder_award_id":"23022","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"},{"id":"https://openalex.org/G7246928032","display_name":null,"funder_award_id":"62032012","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"},{"id":"https://openalex.org/G7940625749","display_name":null,"funder_award_id":"62432012","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"}],"funders":[{"id":"https://openalex.org/F4320321001","display_name":"National Natural Science Foundation of China","ror":"https://ror.org/01h0zpd94"}],"has_content":{"grobid_xml":true,"pdf":true},"content_urls":{"pdf":"https://content.openalex.org/works/W4409657545.pdf","grobid_xml":"https://content.openalex.org/works/W4409657545.grobid-xml"},"referenced_works_count":12,"referenced_works":["https://openalex.org/W2350778671","https://openalex.org/W2962763344","https://openalex.org/W3099700870","https://openalex.org/W4288057740","https://openalex.org/W4301329292","https://openalex.org/W4353004773","https://openalex.org/W4388886073","https://openalex.org/W4391376033","https://openalex.org/W4393147129","https://openalex.org/W4400526126","https://openalex.org/W4400530533","https://openalex.org/W4405181861"],"related_works":["https://openalex.org/W4391375266","https://openalex.org/W2899084033","https://openalex.org/W2748952813","https://openalex.org/W2390279801","https://openalex.org/W4391913857","https://openalex.org/W2358668433","https://openalex.org/W4396701345","https://openalex.org/W2376932109","https://openalex.org/W2001405890","https://openalex.org/W4396696052"],"abstract_inverted_index":{"Large":[0],"language":[1],"models":[2],"(LLMs)":[3],"integrated":[4],"with":[5],"retrieval-augmented":[6],"generation":[7],"(RAG)":[8],"systems":[9],"improve":[10],"accuracy":[11],"by":[12],"leveraging":[13],"external":[14],"knowledge":[15,35,74],"sources.":[16],"However,":[17],"recent":[18],"research":[19],"has":[20],"revealed":[21],"RAG's":[22],"susceptibility":[23],"to":[24,38,68,101,142],"poisoning":[25,108,122],"attacks,":[26],"where":[27],"the":[28,34,61,73,80,92,116,127],"attacker":[29],"injects":[30],"poisoned":[31,70,130],"texts":[32,71,90,131],"into":[33],"database,":[36],"leading":[37],"attacker-desired":[39],"responses.":[40],"Existing":[41],"defenses,":[42],"which":[43],"predominantly":[44],"focus":[45],"on":[46],"inference-time":[47],"mitigation,":[48],"have":[49],"proven":[50],"insufficient":[51],"against":[52,120],"sophisticated":[53],"attacks.":[54,81,123],"In":[55],"this":[56],"paper,":[57],"we":[58],"introduce":[59],"RAGForensics,":[60],"first":[62,85],"traceback":[63,128],"system":[64],"for":[65,79],"RAG,":[66],"designed":[67],"identify":[69],"within":[72],"database":[75,93],"that":[76],"are":[77],"responsible":[78],"RAGForensics":[82,119],"operates":[83],"iteratively,":[84],"retrieving":[86],"a":[87,97,136],"subset":[88],"of":[89,118,129],"from":[91],"and":[94,138],"then":[95],"utilizing":[96],"specially":[98],"crafted":[99],"prompt":[100],"guide":[102],"an":[103],"LLM":[104],"in":[105,132],"detecting":[106],"potential":[107],"texts.":[109],"Empirical":[110],"evaluations":[111],"across":[112],"multiple":[113],"datasets":[114],"demonstrate":[115],"effectiveness":[117],"state-of-the-art":[121],"This":[124],"work":[125],"pioneers":[126],"RAG":[133],"systems,":[134],"providing":[135],"practical":[137],"promising":[139],"defense":[140],"mechanism":[141],"enhance":[143],"their":[144],"security.":[145]},"counts_by_year":[{"year":2026,"cited_by_count":2},{"year":2025,"cited_by_count":2}],"updated_date":"2026-04-10T15:06:20.359241","created_date":"2025-10-10T00:00:00"}
