RAG exploitation attacks target the retrieval pipeline that feeds context to the model. By poisoning knowledge bases, exploiting chunk boundaries, creating embedding collisions, or manipulating retrieval queries, attackers can control what information the model sees and how it responds. As RAG becomes the standard architecture for grounded AI, these attacks are increasingly critical.

Summary

5 attacks total: 3 single-turn, 2 tool-use.

Attacks

Example