Papers
Topics
Authors
Recent
Gemini 2.5 Flash
Gemini 2.5 Flash
41 tokens/sec
GPT-4o
59 tokens/sec
Gemini 2.5 Pro Pro
41 tokens/sec
o3 Pro
7 tokens/sec
GPT-4.1 Pro
50 tokens/sec
DeepSeek R1 via Azure Pro
28 tokens/sec
2000 character limit reached

Black-Box Opinion Manipulation Attacks to Retrieval-Augmented Generation of Large Language Models (2407.13757v1)

Published 18 Jul 2024 in cs.CL, cs.AI, and cs.CR

Abstract: Retrieval-Augmented Generation (RAG) is applied to solve hallucination problems and real-time constraints of LLMs, but it also induces vulnerabilities against retrieval corruption attacks. Existing research mainly explores the unreliability of RAG in white-box and closed-domain QA tasks. In this paper, we aim to reveal the vulnerabilities of Retrieval-Enhanced Generative (RAG) models when faced with black-box attacks for opinion manipulation. We explore the impact of such attacks on user cognition and decision-making, providing new insight to enhance the reliability and security of RAG models. We manipulate the ranking results of the retrieval model in RAG with instruction and use these results as data to train a surrogate model. By employing adversarial retrieval attack methods to the surrogate model, black-box transfer attacks on RAG are further realized. Experiments conducted on opinion datasets across multiple topics show that the proposed attack strategy can significantly alter the opinion polarity of the content generated by RAG. This demonstrates the model's vulnerability and, more importantly, reveals the potential negative impact on user cognition and decision-making, making it easier to mislead users into accepting incorrect or biased information.

User Edit Pencil Streamline Icon: https://streamlinehq.com
Authors (7)
  1. Zhuo Chen (319 papers)
  2. Jiawei Liu (156 papers)
  3. Haotan Liu (2 papers)
  4. Qikai Cheng (10 papers)
  5. Fan Zhang (685 papers)
  6. Wei Lu (325 papers)
  7. Xiaozhong Liu (71 papers)
X Twitter Logo Streamline Icon: https://streamlinehq.com