Skip to content
Search
paperAugust 2026Unreviewed

CamoDocs: A Poisoning Attack Against Retrieval-Augmented Language Models Using Camouflaged Documents

Jaewon Jung, Haizhong Zheng, Hongsun Jang, Jaeyong Song, Beidi Chen, Jinho Lee

Abstract

Retrieval-augmented generation (RAG) augments LLMs with external documents, but public or user-editable sources expose RAG systems to data poisoning: attackers can inject malicious documents to steer outputs toward targeted answers. Existing poisoning attacks often rely on query inclusion, inserting the target query into poisoned documents to improve retrieval; however, this creates lexical and embedding-space artifacts that make them easy to filter. We propose CamoDocs, a poisoning attack that

Categories

Framework mappings

OWASP Top 10 for LLM Applications
  • LLM04Data and Model Poisoning
MITRE ATLAS
  • AML.T0020Poison Training Data

Suggested from the entry's categories.

Cite

@misc{jung2026camodocs,
  title = {{CamoDocs: A Poisoning Attack Against Retrieval-Augmented Language Models Using Camouflaged Documents}},
  author = {Jaewon Jung and Haizhong Zheng and Hongsun Jang and Jaeyong Song and Beidi Chen and Jinho Lee},
  year = {2026},
  month = aug,
  eprint = {2608.28389},
  archivePrefix = {arXiv},
  url = {https://www.semanticscholar.org/paper/8cb58f1bfdd0a241e70a6b4b0058fb0e7c67e6bb}
}