Micro-Collaborative Poisoning: A Distributed Attack on RAG Systems
Quick summary
arXiv:2609.21573v1 Announce Type: cross Abstract: Retrieval-Augmented Generation (RAG) improves large language models by grounding outputs in external knowledge sources, but this dependency also creates a surface for poisoning attacks. This paper introduces Micro-Collaborative Poisoning, a distributed attack in which a false target claim is divided across multiple locally plausible documents instead of being concentrated in a single malicious passage. We evaluate the attack across 108 RAG configurations by varying dataset, retriever architecture, retrieval depth, database composition, number o
Key takeaways
- arXiv:2609.21573v1 Announce Type: cross Abstract: Retrieval-Augmented Generation (RAG) improves large language models by grounding outputs in external knowledge sources, but this dependency also creates a surface for poisoning attacks.
- This paper introduces Micro-Collaborative Poisoning, a distributed attack in which a false target claim is divided across multiple locally plausible documents instead of being concentrated in a single malicious passage.
- We evaluate the attack across 108 RAG configurations by varying dataset, retriever architecture, retrieval depth, database composition, number o
Why it matters
“Micro-Collaborative Poisoning: A Distributed Attack on RAG Systems” highlights the need for repeatable measurement rather than a single impressive demonstration. Independent validation across datasets and clearly stated limitations determine whether a result can guide product decisions.

Member comments