arXiv Artificial Intelligence

Backdoor in the Loop: Compromising Agentic Search via Malicious Retrievers

Backdoor in the Loop: Compromising Agentic Search via Malicious Retrievers

Quick summary

arXiv:2609.37468v1 Announce Type: cross Abstract: Agentic retrieval-augmented generation (RAG) interleaves reasoning with repeated retrieval, giving the retriever influence over both the evidence an agent observes and its subsequent search decisions. We study retriever backdoors that exploit this feedback loop and repurpose weak backdoor purification to conceal their presence. An attacker supplies a compromised retriever checkpoint while leaving the search agent and deployment corpus unchanged. Without corpus write access, the attacker can still suppress useful evidence, persistently retrieve

Key takeaways

  • arXiv:2609.37468v1 Announce Type: cross Abstract: Agentic retrieval-augmented generation (RAG) interleaves reasoning with repeated retrieval, giving the retriever influence over both the evidence an agent observes and its subsequent search decisions.
  • We study retriever backdoors that exploit this feedback loop and repurpose weak backdoor purification to conceal their presence.
  • An attacker supplies a compromised retriever checkpoint while leaving the search agent and deployment corpus unchanged.

Why it matters

“Backdoor in the Loop: Compromising Agentic Search via Malicious Retrievers” highlights the need for repeatable measurement rather than a single impressive demonstration. Independent validation across datasets and clearly stated limitations determine whether a result can guide product decisions.

Kaynak sitede devamını oku: arXiv Artificial Intelligence ↗