InceptionRAG: Dormant-Passage Poisoning Attack Hits 80%+ Success Against RAG Defenses

chaumian · x · 2026-09-16

A new arXiv paper, InceptionRAG, reframes RAG corpus poisoning: instead of embedding an explicit malicious payload in one document, it fragments the attack into a chain of individually harmless "dormant passages" that slip past current mitigations. When retrieved together, they push LLMs to self-deduce target misinformation via multi-hop reasoning. A zeroth-order suffix optimization (ZOSO) method automates authoritative suffix generation for black-box settings. Across 3 datasets and 3 LLMs, the attack exceeds an 80% success rate even under rigorous defenses.

Original post →

More from Safety

Safety channel →