[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"branding":3,"analytics":7,"article-researchers-show-10-poisoned-passages-can-hijack-a-rag-chatbot":10,"sections":35},{"siteName":4,"siteTagline":5,"publisherName":4,"contactEmail":6},"The Revision","Tech news, decoded.","editor@therevision.news",{"gaMeasurementId":8,"adsenseClientId":9},"G-ZW2MV82GYR","ca-pub-8533917693782264",{"article":11},{"id":12,"slug":13,"title":14,"dek":15,"body_md":16,"tags_json":17,"published_at":18,"created_at":19,"updated_at":20,"status":21,"review_note":22,"review_notes":23,"image_url":22,"persona_id":22,"persona_name":22,"section":24,"tags":25,"sources":30,"feedback":34,"feedback_at":22,"cost_usd":34,"total_tokens":34},8695,"researchers-show-10-poisoned-passages-can-hijack-a-rag-chatbot","Researchers Show 10 Poisoned Passages Can Hijack a RAG Chatbot","A new attack called BadRAG shows that a handful of poisoned passages in a knowledge base can make a chatbot refuse to answer or turn hostile.","A handful of booby-trapped documents can hijack what a RAG-powered chatbot tells you.\n\nResearchers describe an attack called BadRAG that targets retrieval-augmented generation systems, the setup where a chatbot pulls in text from an external knowledge base before answering. Many of those knowledge bases are large, unsanitized pools of user-generated content, the kind of thing Google Search draws from when it surfaces sites like Reddit. In the attack, someone slips a small number of malicious passages into that data, built in two stages: first to be retrieved only when a user's query contains a specific attacker-chosen trigger word, then to push the model toward a bad outcome once retrieved, whether that is refusing to answer, flipping sentiment, leaking hidden context, or misusing a tool the model has access to. None of this requires touching the user's question or retraining the model itself.\n\nThe scale is the unsettling part. Just 10 malicious passages, 0.04% of the test corpus, pushed retrieval success to 98.2% and drove negative responses from a baseline of 0.22% up to 72% whenever a trigger word appeared. That is a tiny, cheap payload for a large, targeted effect on any product that quietly ingests public text, which describes most RAG deployments running today.\n\nPrompt injection got the headlines this year. BadRAG is a reminder that the attack surface for LLMs is not just what users type in, it is whatever the model is allowed to go read.","[\"rag\",\"llm-security\",\"data-poisoning\",\"ai-research\"]","2026-09-30T04:00:00.000Z","2026-09-30T19:52:21.148Z","2026-09-30T19:52:26.614Z","published",null,[],"security",[26,27,28,29],"rag","llm-security","data-poisoning","ai-research",[31],{"name":32,"url":33},"arXiv cs.AI","https:\u002F\u002Farxiv.org\u002Fabs\u002F2406.00083",0,{"sections":36},[37,41,44,48,53,58,62,67,72,76,81,86,91,96],{"name":38,"slug":39,"count":40,"latest_published_at":18},"AI","ai",5184,{"name":42,"slug":24,"count":43,"latest_published_at":18},"Security",791,{"name":45,"slug":46,"count":47,"latest_published_at":18},"Policy","policy",417,{"name":49,"slug":50,"count":51,"latest_published_at":52},"Deals","deals",284,"2026-09-29T21:00:00.000Z",{"name":54,"slug":55,"count":56,"latest_published_at":57},"Hardware","hardware",194,"2026-09-29T13:16:04.000Z",{"name":59,"slug":60,"count":61,"latest_published_at":18},"Science","science",155,{"name":63,"slug":64,"count":65,"latest_published_at":66},"Consumer Tech","consumer-tech",142,"2026-09-29T18:38:03.000Z",{"name":68,"slug":69,"count":70,"latest_published_at":71},"Software","software",91,"2026-09-25T20:55:00.000Z",{"name":73,"slug":74,"count":75,"latest_published_at":18},"Dev Tools","dev-tools",90,{"name":77,"slug":78,"count":79,"latest_published_at":80},"Startups","startups",83,"2026-09-29T21:51:36.000Z",{"name":82,"slug":83,"count":84,"latest_published_at":85},"General","general",49,"2026-09-28T16:44:57.000Z",{"name":87,"slug":88,"count":89,"latest_published_at":90},"Gaming","gaming",48,"2026-09-25T18:35:21.000Z",{"name":92,"slug":93,"count":94,"latest_published_at":95},"Reviews","reviews",31,"2026-09-28T14:31:34.000Z",{"name":97,"slug":98,"count":99,"latest_published_at":100},"How-To","how-to",6,"2026-06-16T09:00:00.000Z"]