{"id":"https://openalex.org/W7152996190","doi":"https://doi.org/10.48550/arxiv.2604.07403","title":"RefineRAG: Word-Level Poisoning Attacks via Retriever-Guided Text Refinement","display_name":"RefineRAG: Word-Level Poisoning Attacks via Retriever-Guided Text Refinement","publication_year":2026,"publication_date":"2026-04-08","ids":{"openalex":"https://openalex.org/W7152996190","doi":"https://doi.org/10.48550/arxiv.2604.07403"},"language":null,"primary_location":{"id":"doi:10.48550/arxiv.2604.07403","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2604.07403","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":null,"is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"article"},"type":"preprint","indexed_in":["datacite"],"open_access":{"is_oa":true,"oa_status":"green","oa_url":"https://doi.org/10.48550/arxiv.2604.07403","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5133330212","display_name":"Ziye Wang","orcid":null},"institutions":[],"countries":[],"is_corresponding":true,"raw_author_name":"Wang, Ziye","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5133327473","display_name":"Guanyu Wang","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Wang, Guanyu","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"last","author":{"id":"https://openalex.org/A5133350855","display_name":"Kailong Wang","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Wang, Kailong","raw_affiliation_strings":[],"affiliations":[]}],"institutions":[],"countries_distinct_count":0,"institutions_distinct_count":3,"corresponding_author_ids":["https://openalex.org/A5133330212"],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":null,"has_fulltext":false,"cited_by_count":0,"citation_normalized_percentile":null,"cited_by_percentile_year":null,"biblio":{"volume":null,"issue":null,"first_page":null,"last_page":null},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10028","display_name":"Topic Modeling","score":0.4481000006198883,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10028","display_name":"Topic Modeling","score":0.4481000006198883,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.2508000135421753,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12262","display_name":"Hate Speech and Cyberbullying Detection","score":0.04699999839067459,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/vulnerability","display_name":"Vulnerability (computing)","score":0.5339999794960022},{"id":"https://openalex.org/keywords/grammar","display_name":"Grammar","score":0.5332000255584717},{"id":"https://openalex.org/keywords/bridge","display_name":"Bridge (graph theory)","score":0.4934999942779541},{"id":"https://openalex.org/keywords/macro","display_name":"Macro","score":0.4027999937534332},{"id":"https://openalex.org/keywords/repetition","display_name":"Repetition (rhetorical device)","score":0.38690000772476196}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7102000117301941},{"id":"https://openalex.org/C95713431","wikidata":"https://www.wikidata.org/wiki/Q631425","display_name":"Vulnerability (computing)","level":2,"score":0.5339999794960022},{"id":"https://openalex.org/C26022165","wikidata":"https://www.wikidata.org/wiki/Q8091","display_name":"Grammar","level":2,"score":0.5332000255584717},{"id":"https://openalex.org/C100776233","wikidata":"https://www.wikidata.org/wiki/Q2532492","display_name":"Bridge (graph theory)","level":2,"score":0.4934999942779541},{"id":"https://openalex.org/C166955791","wikidata":"https://www.wikidata.org/wiki/Q629579","display_name":"Macro","level":2,"score":0.4027999937534332},{"id":"https://openalex.org/C2776141515","wikidata":"https://www.wikidata.org/wiki/Q1274479","display_name":"Repetition (rhetorical device)","level":2,"score":0.38690000772476196},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.35850000381469727},{"id":"https://openalex.org/C184337299","wikidata":"https://www.wikidata.org/wiki/Q1437428","display_name":"Semantics (computer science)","level":2,"score":0.3208000063896179},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.31709998846054077},{"id":"https://openalex.org/C137293760","wikidata":"https://www.wikidata.org/wiki/Q3621696","display_name":"Language model","level":2,"score":0.303600013256073},{"id":"https://openalex.org/C204321447","wikidata":"https://www.wikidata.org/wiki/Q30642","display_name":"Natural language processing","level":1,"score":0.29789999127388},{"id":"https://openalex.org/C2780791683","wikidata":"https://www.wikidata.org/wiki/Q846785","display_name":"Action (physics)","level":2,"score":0.2867000102996826}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.48550/arxiv.2604.07403","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2604.07403","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":null,"is_accepted":false,"is_published":null,"raw_source_name":null,"raw_type":"article"}],"best_oa_location":{"id":"doi:10.48550/arxiv.2604.07403","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2604.07403","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":null,"is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"article"},"sustainable_development_goals":[{"score":0.4058540165424347,"display_name":"Peace, Justice and strong institutions","id":"https://metadata.un.org/sdg/16"}],"awards":[],"funders":[],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":0,"referenced_works":[],"related_works":[],"abstract_inverted_index":{"Retrieval-Augmented":[0],"Generation":[1,56],"(RAG)":[2],"significantly":[3],"enhances":[4],"Large":[5],"Language":[6],"Models":[7],"(LLMs),":[8],"but":[9],"simultaneously":[10],"exposes":[11],"a":[12,38,45,69,91,121],"critical":[13],"vulnerability":[14],"to":[15,27,61,72,116],"knowledge":[16],"poisoning":[17,43],"attacks.":[18],"Existing":[19],"attack":[20],"methods":[21],"like":[22],"PoisonedRAG":[23],"remain":[24],"detectable":[25],"due":[26],"coarse-grained":[28],"separate-and-concatenate":[29],"strategies.":[30],"To":[31],"bridge":[32],"this":[33],"gap,":[34],"we":[35],"propose":[36],"RefineRAG,":[37],"novel":[39],"framework":[40],"that":[41,85],"treats":[42],"as":[44],"holistic":[46],"word-level":[47],"refinement":[48],"problem.":[49],"It":[50],"operates":[51],"in":[52],"two":[53],"stages:":[54],"Macro":[55],"produces":[57],"toxic":[58],"seeds":[59],"guaranteed":[60],"induce":[62],"target":[63],"answers,":[64],"while":[65,98],"Micro":[66],"Refinement":[67],"employs":[68],"retriever-in-the-loop":[70],"optimization":[71],"maximize":[73],"retrieval":[74],"priority":[75],"without":[76],"compromising":[77],"naturalness.":[78],"Evaluations":[79],"on":[80,96],"NQ":[81],"and":[82,104],"MSMARCO":[83],"demonstrate":[84],"RefineRAG":[86],"achieves":[87],"state-of-the-art":[88],"effectiveness,":[89],"securing":[90],"90%":[92],"Attack":[93],"Success":[94],"Rate":[95],"NQ,":[97],"registering":[99],"the":[100],"lowest":[101],"grammar":[102],"errors":[103],"repetition":[105],"rates":[106],"among":[107],"all":[108],"baselines.":[109],"Crucially,":[110],"our":[111],"proxy-optimized":[112],"attacks":[113],"successfully":[114],"transfer":[115],"black-box":[117],"victim":[118],"systems,":[119],"highlighting":[120],"severe":[122],"practical":[123],"threat.":[124]},"counts_by_year":[],"updated_date":"2026-04-11T06:19:08.300824","created_date":"2026-04-11T00:00:00"}
