HNHacker News
TopNewBestAskShowJobs

aminerj

95 karma · joined July 9, 2018

AI security researcher. 15+ years in critical infrastructure, defense, and cloud. Writing and building labs on agentic AI security @ aminrj.com
submissionscomments
aminerj··on Document poisoning in RAG systems: How attackers corrupt AI's sources
You're right, and this is an underappreciated point. The "attacker" framing can actually obscure the more common risk: organic knowledge base degradation over time. The poisoning attack is just the adversarial extreme of a problem that exists in every large document store.

The model robustness angle is valid but I'd push back slightly on it being sufficient as a primary control. The model risk / backtesting framing is exactly right for the generation side. Where RAG diverges from traditional ML is that the "training data" is mutable at runtime (any authenticated user or pipeline can change what the model sees without retraining).