August 2026Unreviewed
DenialRAG: Single-Document RAG Poisoning via Embedded Parametric Denial
Abay Zhurekbay, Tao Liu, Fan Li
Abstract
Retrieval-augmented generation (RAG) systems are vulnerable to corpus poisoning: an attacker who inserts a crafted document into the retrieval corpus can steer the underlying large language model (LLM) toward an attacker-chosen wrong answer. Prior single-document attacks typically avoid explicitly naming and refuting the correct answer inside the poisoned passage. In this paper, we examine a complementary design and propose \emph{DenialRAG}, a single-document poisoning attack that explicitly nam
Categories
Framework mappings
OWASP Top 10 for LLM Applications
- LLM04Data and Model Poisoning
MITRE ATLAS
- AML.T0020Poison Training Data
Suggested from the entry's categories.
Cite
@misc{zhurekbay2026denialrag,
title = {{DenialRAG: Single-Document RAG Poisoning via Embedded Parametric Denial}},
author = {Abay Zhurekbay and Tao Liu and Fan Li},
year = {2026},
month = aug,
eprint = {2608.02678},
archivePrefix = {arXiv},
url = {https://www.semanticscholar.org/paper/498d48436d075c7046441802b9b23026a318c81a}
}