检索增强生成系统的对抗威胁向量与风险缓解
Adversarial Threat Vectors and Risk Mitigation for Retrieval-Augmented Generation Systems
- Fire Mountain Labs
机构由 AI 辅助整理,请以论文原文为准。
AI总结:
本文分析了检索增强生成(RAG)系统面临的提示注入、数据投毒和对抗性查询操纵等主要对抗威胁,并从风险管理视角提出了包含输入验证、对抗训练和实时监控的优先控制列表以缓解风险。
AI中文摘要:
检索增强生成(RAG)系统集成了大型语言模型(LLMs)与外部知识源,容易受到一系列对抗性攻击向量的攻击。本文通过近期行业采用趋势考察了RAG系统的重要性,并识别了RAG的主要攻击向量:提示注入、数据投毒和对抗性查询操纵。我们在风险管理视角下分析这些威胁,并提出稳健的优先控制列表,包括输入验证、对抗训练和实时监控等风险缓解行动。
英文摘要:
Retrieval-Augmented Generation (RAG) systems, which integrate Large Language Models (LLMs) with external knowledge sources, are vulnerable to a range of adversarial attack vectors. This paper examines the importance of RAG systems through recent industry adoption trends and identifies the prominent attack vectors for RAG: prompt injection, data poisoning, and adversarial query manipulation. We analyze these threats under risk management lens, and propose robust prioritized control list that includes risk-mitigating actions like input validation, adversarial training, and real-time monitoring.