Detector-aware graph dispersion against RAGSieve

Investigate detector-aware graph dispersion strategies that enable poisoning attacks to evade both the semantic-similarity and lexical-diversity conditions used by RAGSieve's corpus-local graph detector.

Background

RAGSieve's offline RSG detector identifies coordinated poisoning by retaining document pairs that are semantically similar but lexically distinct and comparing their local graph density against a document-specific neighborhood floor. The paper acknowledges that its evaluated attacks were not jointly optimized against these two detection conditions.

The unresolved problem is to determine whether attackers can deliberately disperse poisoned documents through the corpus graph while simultaneously satisfying or evading RSG's semantic and lexical criteria. Solving this problem would clarify the robustness of RSG against adaptive, detector-aware poisoning attacks.

References

Detector-aware graph dispersion therefore remains open.

RAGSieve: Self-Referenced Local Contrast for Knowledge-Poison Detection in Retrieval-Augmented Generation  (2608.13010 - Xu et al., 13 Aug 2026) in Section 7, Discussion and Limitations

We cannot exclude the possibility that clones copy implementations while rewriting tool descriptions, which our method would miss and theirs would catch; if that is what is happening, the gap between code-level and interface-level duplication is itself a result worth reporting.

What a Random Draw from the MCP Registry Contains, and What Tool-Use Benchmarks Contain Instead  (2609.10962 - Afsar, 10 Sep 2026) in Section 7, Threats to validity, paragraph “The handshake filter, tested directly”