Securing Retrieval-Augmented Generation: A Taxonomy of Attacks, Defenses, and Future Directions
保障检索增强生成:攻击、防御与未来方向的分类法
机构 * The Hong Kong Polytechnic University(香港理工大学) ; The Hong Kong University of Science and Technology (Guangzhou)(香港科学与技术大学(广州))
AI总结 本文提出SLOT分类法,从攻击面、防御层、目标(遵循CIA属性)和攻击目标四个维度系统化梳理检索增强生成(RAG)的安全风险与防御,并指出知识访问管道中的结构性错配,最后展望未来方向。
Comments We have curated a paper list on RAG security in https://github.com/TreeAI-Lab/Awesome-RAG-Security, and we warmly welcome authors who wish to have their new work included to contact us via email