כתבה
arXiv cs.CL ·
Salience Induction against Multi-Hop RAG Agents: Threat and Defense
תקציר מקורי באנגליתarXiv:2607.17535v1 Announce Type: cross Abstract: Agentic retrieval-augmented generation (RAG) systems increasingly retrieve external evidence and orchestrate tools for knowledge-intensive applications. In Multi-Hop question answering, agents chain facts across documents. Existing defenses focus on content poisoning, which injects false facts, and prompt injection, which embeds directives. We identify a third attack surface: the salience channel, through which fact position, emphasis, framing, and semantic proximity can redirect reasoning even when all retrieved claims are true and no instructions are present. We formalize Salience Induction as truth-preserving edits that redirect Multi-Hop attribute binding while leaving the retrieval trace semantically intact. We define six Salience-Edit
קרא במקור המקורי
arxiv.org
פתח כתבה מקורית