AltaySec · ATLAS 2026.07
AML.T0071

False RAG Entry Injection

Bu tekniğin yerleşik Türkçe adı henüz terminoloji kanonuna eklenmedi; İngilizce adı gösteriliyor.

C · Açıklama (tarayıcıda dürüstçe simüle edilemez) AML.TA0007 · Savunmadan Kaçınma

Açıklama

Türkçe çeviri henüz mevcut değil; resmi İngilizce açıklama gösteriliyor (uydurma çeviri yapılmaz).

Adversaries may introduce false entries into a victim's retrieval augmented generation (RAG) database. Content designed to be interpreted as a document by the large language model (LLM) used in the RAG system is included in a data source being ingested into the RAG database. When a RAG entry containing the false document is retrieved, the LLM is tricked into treating part of the retrieved content as a false RAG result. By including a false RAG document inside of a regular RAG entry, it bypasses data monitoring tools. It also prevents the document from being deleted directly. The adversary may use discovered system keywords to learn how to instruct a particular LLM to treat content as a RAG entry. They may be able to manipulate the injected entry's metadata including document title, author, and creation date.

Dürüstlük rozeti gerekçesi

Bu teknik gerçek bir savunma yığınına karşı ölçülmelidir; tarayıcıda en fazla basit bir filtre-karşı-filtre gösterimi dürüst olur.

Kaynak

← Matrise dön