Session
RAG Poisoning: When Your AI's Knowledge Base Becomes the Attack
RAG is often presented as the safer way to ground an LLM in trusted information. But what happens when the information you retrieve is the thing an attacker controls?
A malicious document does not need to exploit the model directly. If it enters a knowledge base, gets embedded and is retrieved at the right moment, it can influence what the model sees and ultimately what the application does.
This session explores the security boundary around RAG systems, focusing on data poisoning, malicious documents, retrieval manipulation, cross-context leakage and unsafe trust in retrieved content.
Through a controlled demonstration, we will start with a normal RAG application and introduce poisoned content into its knowledge base. We will then trace how that content moves through ingestion, retrieval and generation, and examine the controls that can prevent or limit the attack.
We will finish with a practical defensive architecture covering data provenance, ingestion validation, access control, retrieval filtering, content trust boundaries and monitoring.
The goal is to stop treating the vector database as a passive knowledge store and start treating the entire RAG pipeline as a security boundary.
Monica R
Software Development Engineer @ Autodesk - Speaks AI, Tech & Careers
Bengaluru, India
Links
Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.
Jump to top