发表机构
Duke University(杜克大学)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
该研究提出惰性接地攻击,即搜索智能体被邻近问题的事实证据误导,实验显示其可降低准确率最高17.3个百分点,表明需防御事实证据的误用。
AI 中文摘要
搜索智能体通过将答案基于检索到的网络证据来减少幻觉。然而,对检索的依赖也形成了攻击面:包含虚假或恶意文档的中毒语料库可能导致智能体重现错误信息。我们证明虚假性并非必要——搜索智能体可被邻近问题的事实证据误导,采用该邻近答案,即便其不回答当前问题。我们将此缺陷称为惰性接地。我们通过基准问题的答案改写产生的邻近证据来揭示惰性接地:每个文档真实支持邻近改写后的问题,但却被呈现给原始问题。在12组模型-基准对中,邻近证据平均降低准确率5.9个百分点,最高降低17.3个百分点,且在所有设置中均诱导邻近答案的采用。当邻近证据出现较晚或更具答案指向性时,效果更强。我们的结果表明,稳健的搜索智能体不仅必须防御错误信息,还必须防御事实证据的误用。代码公开于this https URL。
英文摘要
Search agents mitigate hallucination by grounding their answers in retrieved web results. However, retrieval-based approaches also introduce an attack surface: agents may cite misinformation from poisoned search corpora containing false or malicious documents. We demonstrate that, in some cases, search agents' reasoning and responses may be steered by completely factual but distracting information. We refer to this failure as lazy grounding. We expose lazy grounding by injecting nearby evidence from answer-changing rewrites of benchmark questions into the search corpora. Each document contains factual evidence that supports a neighboring rewritten question but is retrieved for the original question. Across 12 model-benchmark pairs, the attack causes the accuracy of search agents' responses to drop by 5.9 points on average and by up to 17.3 points, while inducing nearby-answer adoption in every setting. The effect is even stronger when nearby evidence appears later or is more answer-shaped. Our results show that robust search agents must defend against not only misinformation but also the misapplication of factual evidence. The code is publicly available at https://github.com/frankyzha/lazy-grounding.
CommentsAccepted to EMNLP 2026 (Main Conference). Code: https://github.com/frankyzha/lazy-grounding