arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2610.11893cs.CR

检索增强生成系统的安全元模型

A Security Meta-Model for Retrieval-Augmented Generation Systems

Steve Nouyep, Sébastien Salva, Maxime Puys

首次发表
浏览论文内容

中文总结 AI 辅助

本文提出一种RAG系统安全元模型,通过分析43篇文献构建含威胁与补救措施的目录,可生成部署相关风险概况,揭示攻防研究失衡等问题,验证了其在多类型RAG配置中的适用性。

中文摘要 AI 辅助

检索增强生成(RAG)系统通过多阶段流水线为大语言模型(LLM)补充外部知识,该架构虽能提升生成答案的事实依据性,但引入了超出独立LLM的结构性攻击面。本文提出一种安全元模型,用于捕获RAG攻击面、攻击、弱点、风险与CIA影响(保密性、完整性、可用性)之间的显式因果关系,旨在为安全工程师提供结构化且易用的框架,以收集和评估其RAG部署相关的风险、弱点与缓解措施。该元模型通过对2023至2026年的43篇公开文献进行迭代结构化分析设计,并实例化为包含文献中报告的安全威胁与补救措施的目录。根据部署配置筛选该目录可生成适用于该部署的风险概况,交互式网页可视化工具允许用户以图形式浏览目录、追踪因果链并探索利益相关者特定视图。对目录的分析显示,以攻击为中心与以防御为中心的研究存在持续失衡,威胁集中于数据摄入环节,且存在影响输出完整性的覆盖缺口;覆盖情况参照OWASP LLM Top 10评估,其操作适用性在文本型、图基型与多模态RAG配置中均得到验证。

英文摘要

Retrieval-Augmented Generation (RAG) systems extend large language models (LLMs) with external knowledge through a multi-stage pipeline. While this architecture can improve the factual grounding of generated answers, it introduces structural attack surfaces that extend beyond those of standalone LLMs. In this paper, we introduce a security meta-model that captures explicit causal relationships between RAG surfaces, attacks, weaknesses, risks, and CIA impact (Confidentiality, Integrity, Availability). Its purpose is to provide security engineers with a structured and user-friendly framework for gathering and assessing the risks, weaknesses, and mitigations relevant to their RAG deployment. We designed the meta-model through an iterative, structured analysis of 43~publications (2023--2026) and instantiated it as a catalog populated with the security threats and remediations reported in the literature. Filtering the catalog according to a deployment configuration produces a risk profile containing the risks applicable to that deployment. An interactive web visualizer lets users navigate the catalog as a graph, follow causal chains, and explore stakeholder-specific views. Analysis of the catalog revealed a persistent imbalance between attack-focused and defense-focused research, a concentration of threats at ingestion, and coverage gaps affecting output integrity. Coverage is assessed against the OWASP LLM Top~10, and operational applicability is illustrated across textual, graph-based, and multimodal RAG configurations.

发表机构

  • Université Clermont Auvergne(克莱蒙奥弗涅大学)

机构由 AI 辅助整理,请以论文原文为准。

↑