Conceptual

Corpus Poisoning and Prompt-Injection Attacks on Retrieval Systems

Adversarial attacks that insert crafted documents into the knowledge base of a retrieval-augmented system so that they are retrieved for a target query and steer or override the model's output. Covers how injected passages are optimized to rank highly for chosen queries, the difference from direct prompt injection, and why a small number of poisoned documents can dominate the retrieved context.