{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,3]],"date-time":"2026-06-03T03:02:56Z","timestamp":1780455776364,"version":"3.54.1"},"reference-count":45,"publisher":"Elsevier BV","license":[{"start":{"date-parts":[[2026,11,1]],"date-time":"2026-11-01T00:00:00Z","timestamp":1793491200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/tdm\/userlicense\/1.0\/"},{"start":{"date-parts":[[2026,11,1]],"date-time":"2026-11-01T00:00:00Z","timestamp":1793491200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/legal\/tdmrep-license"},{"start":{"date-parts":[[2026,11,1]],"date-time":"2026-11-01T00:00:00Z","timestamp":1793491200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-017"},{"start":{"date-parts":[[2026,11,1]],"date-time":"2026-11-01T00:00:00Z","timestamp":1793491200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"},{"start":{"date-parts":[[2026,11,1]],"date-time":"2026-11-01T00:00:00Z","timestamp":1793491200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-012"},{"start":{"date-parts":[[2026,11,1]],"date-time":"2026-11-01T00:00:00Z","timestamp":1793491200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2026,11,1]],"date-time":"2026-11-01T00:00:00Z","timestamp":1793491200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-004"}],"funder":[{"DOI":"10.13039\/100017837","name":"Wuxi Science and Technology Association","doi-asserted-by":"publisher","id":[{"id":"10.13039\/100017837","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100010854","name":"Jiangsu Provincial Health Commission","doi-asserted-by":"publisher","id":[{"id":"10.13039\/501100010854","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100010023","name":"Natural Science Research of Jiangsu Higher Education Institutions of China","doi-asserted-by":"publisher","id":[{"id":"10.13039\/501100010023","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["elsevier.com","sciencedirect.com"],"crossmark-restriction":true},"short-container-title":["Neural Networks"],"published-print":{"date-parts":[[2026,11]]},"DOI":"10.1016\/j.neunet.2026.109192","type":"journal-article","created":{"date-parts":[[2026,5,30]],"date-time":"2026-05-30T15:31:47Z","timestamp":1780155107000},"page":"109192","update-policy":"https:\/\/doi.org\/10.1016\/elsevier_cm_policy","source":"Crossref","is-referenced-by-count":0,"special_numbering":"C","title":["Fine-grained hierarchical multi-round iterative semantic optimization attack method for RAG systems"],"prefix":"10.1016","volume":"203","author":[{"given":"Qidong","family":"Chen","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-6768-8394","authenticated-orcid":false,"given":"Vasile","family":"Palade","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5051-163X","authenticated-orcid":false,"given":"Zihao","family":"Yu","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Ruixiang","family":"Deng","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9824-4294","authenticated-orcid":false,"given":"Jun","family":"Sun","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Hao","family":"Wu","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"78","reference":[{"key":"10.1016\/j.neunet.2026.109192_bib0001","unstructured":"Achiam, J., Adler, S., Agarwal, S., Ahmad, L., Akkaya, I., Aleman, F. L., Almeida, D., Altenschmidt, J., Altman, S., Anadkat, S. et al. (2023). GPT-4 technical report. arXiv preprint arXiv: 2303.08774."},{"key":"10.1016\/j.neunet.2026.109192_bib0002","unstructured":"Aguilera-Martinez, F., & Berzal, F. (2025). LLM security: Vulnerabilities, attacks, defenses, and countermeasures. arXiv preprint arXiv: 2505.01177."},{"key":"10.1016\/j.neunet.2026.109192_bib0003","article-title":"Transforming healthcare education: Harnessing large language models for frontline health worker capacity building using retrieval-augmented generation","author":"Al Ghadban","year":"2023","journal-title":"medRxiv, Preprint"},{"key":"10.1016\/j.neunet.2026.109192_bib0004","unstructured":"Anil, R., Dai, A. M., Firat, O., Johnson, M., Lepikhin, D., Passos, A., Shakeri, S., Taropa, E., Bailey, P., Chen, Z. et al. (2023). Palm 2 technical report. arXiv preprint arXiv: 2305.10403."},{"key":"10.1016\/j.neunet.2026.109192_bib0005","unstructured":"Bai, J., Bai, S., Chu, Y., Cui, Z., Dang, K., Deng, X., Fan, Y., Ge, W., Han, Y., Huang, F. et al. (2023). Qwen technical report. arXiv preprint arXiv: 2309.16609."},{"key":"10.1016\/j.neunet.2026.109192_bib0006","series-title":"International conference on machine learning","first-page":"2206","article-title":"Improving language models by retrieving from trillions of tokens","author":"Borgeaud","year":"2022"},{"key":"10.1016\/j.neunet.2026.109192_bib0007","first-page":"1877","article-title":"Language models are few-shot learners","volume":"33","author":"Brown","year":"2020","journal-title":"Advances in Neural Information Processing Systems"},{"key":"10.1016\/j.neunet.2026.109192_bib0008","series-title":"ICLR 2024 workshop on secure and trustworthy large language models","article-title":"PANDORA: Detailed LLM jailbreaking via collaborated phishing agents with decomposed reasoning","author":"Chen","year":"2024"},{"key":"10.1016\/j.neunet.2026.109192_bib0009","series-title":"Proceedings of the AAAI conference on artificial intelligence","first-page":"10581","article-title":"Synthetic disinformation attacks on automated fact verification systems","volume":"vol. 36","author":"Du","year":"2022"},{"key":"10.1016\/j.neunet.2026.109192_bib0010","series-title":"Proceedings of the 56th annual meeting of the association for computational linguistics (volume 2: Short papers)","first-page":"31","article-title":"HotFlip: White-box adversarial examples for text classification","author":"Ebrahimi","year":"2018"},{"issue":"2","key":"10.1016\/j.neunet.2026.109192_bib0011","doi-asserted-by":"crossref","first-page":"661","DOI":"10.1162\/coli_a_00561","article-title":"LLM-based NLG evaluation: Current status and challenges","volume":"51","author":"Gao","year":"2025","journal-title":"Computational Linguistics"},{"key":"10.1016\/j.neunet.2026.109192_bib0012","series-title":"Findings of the association for computational linguistics: EMNLP 2023","first-page":"10136","article-title":"Demystifying prompts in language models via perplexity estimation","author":"Gonen","year":"2023"},{"key":"10.1016\/j.neunet.2026.109192_bib0013","unstructured":"Guo, D., Yang, D., Zhang, H., Song, J., Zhang, R., Xu, R., Zhu, Q., Ma, S., Wang, P., Bi, X. et al. (2025). DeepSeek-R1: Incentivizing reasoning capability in llms via reinforcement learning. arXiv preprint arXiv: 2501.12948."},{"issue":"12","key":"10.1016\/j.neunet.2026.109192_bib0014","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3571730","article-title":"Survey of hallucination in natural language generation","volume":"55","author":"Ji","year":"2023","journal-title":"ACM Computing Surveys"},{"key":"10.1016\/j.neunet.2026.109192_bib0015","doi-asserted-by":"crossref","first-page":"453","DOI":"10.1162\/tacl_a_00276","article-title":"Natural questions: A benchmark for question answering research","volume":"7","author":"Kwiatkowski","year":"2019","journal-title":"Transactions of the Association for Computational Linguistics"},{"key":"10.1016\/j.neunet.2026.109192_bib0016","first-page":"9459","article-title":"Retrieval-augmented generation for knowledge-intensive NLP tasks","volume":"33","author":"Lewis","year":"2020","journal-title":"Advances in Neural Information Processing Systems"},{"key":"10.1016\/j.neunet.2026.109192_bib0017","series-title":"2023\u202fIEEE Symposium on security and privacy (SP)","first-page":"1893","article-title":"3DFed: Adaptive and extensible framework for covert backdoor attack in federated learning","author":"Li","year":"2023"},{"issue":"3","key":"10.1016\/j.neunet.2026.109192_bib0018","first-page":"1","article-title":"Poison attack and poison detection on deep source code processing models","volume":"33","author":"Li","year":"2024","journal-title":"ACM Transactions on Software Engineering and Methodology"},{"key":"10.1016\/j.neunet.2026.109192_bib0019","series-title":"European conference on information retrieval","first-page":"95","article-title":"Reproducing hotflip for corpus poisoning attacks in dense retrieval","author":"Li","year":"2025"},{"key":"10.1016\/j.neunet.2026.109192_bib0020","unstructured":"Liu, Y., Deng, G., Li, Y., Wang, K., Wang, Z., Wang, X., Zhang, T., Liu, Y., Wang, H., Zheng, Y. et al. (2023). Prompt injection attack against LLM-integrated applications. arXiv preprint arXiv: 2306.05499."},{"key":"10.1016\/j.neunet.2026.109192_bib0021","series-title":"33rd USENIX security symposium (USENIX security 24)","first-page":"1831","article-title":"Formalizing and benchmarking prompt injection attacks and defenses","author":"Liu","year":"2024"},{"key":"10.1016\/j.neunet.2026.109192_bib0022","series-title":"European conference on information retrieval","first-page":"239","article-title":"Poison-RAG: Adversarial data poisoning attacks on retrieval-augmented generation in recommender systems","author":"Nazary","year":"2025"},{"key":"10.1016\/j.neunet.2026.109192_bib0023","first-page":"660","article-title":"MS MARCO: A human generated machine reading comprehension dataset","volume":"2640","author":"Nguyen","year":"2016","journal-title":"Choice"},{"key":"10.1016\/j.neunet.2026.109192_bib0024","series-title":"Proceedings of the 2022 conference on empirical methods in natural language processing","first-page":"9844","article-title":"Large dual encoders are generalizable retrievers","author":"Ni","year":"2022"},{"key":"10.1016\/j.neunet.2026.109192_bib0025","series-title":"Findings of the association for computational linguistics: EMNLP 2023","first-page":"1389","article-title":"On the risk of misinformation pollution with large language models","author":"Pan","year":"2023"},{"key":"10.1016\/j.neunet.2026.109192_bib0026","series-title":"2020\u202fIEEE Symposium on security and privacy (SP)","first-page":"1295","article-title":"Humpty dumpty: Controlling word meanings via corpus poisoning","author":"Schuster","year":"2020"},{"key":"10.1016\/j.neunet.2026.109192_bib0027","series-title":"Proceedings of the 2024 on ACM SIGSAC conference on computer and communications security","first-page":"660","article-title":"Optimization-based prompt injection attack to llm-as-a-judge","author":"Shi","year":"2024"},{"issue":"3","key":"10.1016\/j.neunet.2026.109192_bib0028","doi-asserted-by":"crossref","first-page":"1958","DOI":"10.1109\/TPAMI.2024.3511621","article-title":"Divide-and-conquer: Confluent triple-flow network for RGB-t salient object detection","volume":"47","author":"Tang","year":"2024","journal-title":"IEEE Transactions on Pattern Analysis and Machine Intelligence"},{"key":"10.1016\/j.neunet.2026.109192_bib0029","doi-asserted-by":"crossref","DOI":"10.1016\/j.patcog.2022.108792","article-title":"Learning attention-guided pyramidal features for few-shot fine-grained recognition","volume":"130","author":"Tang","year":"2022","journal-title":"Pattern Recognition"},{"key":"10.1016\/j.neunet.2026.109192_bib0030","unstructured":"G. Team, Anil, R., Borgeaud, S., Alayrac, J.-B., Yu, J., Soricut, R., Schalkwyk, J., Dai, A. M., Hauth, A., Millican, K. et al. (2023). Gemini: A family of highly capable multimodal models. arXiv preprint arXiv: 2312.11805."},{"key":"10.1016\/j.neunet.2026.109192_bib0031","unstructured":"Thoppilan, R., De Freitas, D., Hall, J., Shazeer, N., Kulshreshtha, A., Cheng, H.-T., Jin, A., Bos, T., Baker, L., Du, Y. et al. (2022). LaMDA: Language models for dialog applications. arXiv preprint arXiv: 2302.13971."},{"key":"10.1016\/j.neunet.2026.109192_bib0032","unstructured":"Touvron, H., Lavril, T., Izacard, G., Martinet, X., Lachaux, M.-A., Lacroix, T., Rozi\u00e8re, B., Goyal, N., Hambro, E., Azhar, F. et al. (2023). LLaMA: Open and efficient foundation language models. arXiv preprint arXiv: 2302.13971."},{"issue":"5","key":"10.1016\/j.neunet.2026.109192_bib0033","doi-asserted-by":"crossref","first-page":"1115","DOI":"10.1007\/s10439-023-03327-6","article-title":"Potential for GPT technology to optimize future clinical decision-making using retrieval-augmented generation","volume":"52","author":"Wang","year":"2024","journal-title":"Annals of Biomedical Engineering"},{"key":"10.1016\/j.neunet.2026.109192_bib0034","series-title":"Proceedings of the 41st international conference on machine learning","first-page":"53366","article-title":"Next-GPT: Any-to-any multimodal LLM","author":"Wu","year":"2024"},{"key":"10.1016\/j.neunet.2026.109192_bib0035","series-title":"Proceedings of the 47th international ACM SIGIR conference on research and development in information retrieval","first-page":"641","article-title":"C-Pack: Packed resources for general Chinese embeddings","author":"Xiao","year":"2024"},{"key":"10.1016\/j.neunet.2026.109192_bib0036","unstructured":"Xue, J., Zheng, M., Hu, Y., Liu, F., Chen, X., & Lou, Q. (2024). BadRAG: Identifying vulnerabilities in retrieval augmented generation of large language models. arXiv preprint arXiv: 2406.00083."},{"key":"10.1016\/j.neunet.2026.109192_bib0037","series-title":"Proceedings of the 2018 conference on empirical methods in natural language processing","first-page":"2369","article-title":"HotpotQA: A dataset for diverse, explainable multi-hop question answering","author":"Yang","year":"2018"},{"issue":"2","key":"10.1016\/j.neunet.2026.109192_bib0038","doi-asserted-by":"crossref","DOI":"10.1016\/j.hcc.2024.100211","article-title":"A survey on large language model (LLM) security and privacy: The good, the bad, and the ugly","volume":"4","author":"Yao","year":"2024","journal-title":"High-Confidence Computing"},{"key":"10.1016\/j.neunet.2026.109192_bib0039","doi-asserted-by":"crossref","DOI":"10.1016\/j.eswa.2022.118101","article-title":"Data poisoning attacks against machine learning algorithms","volume":"208","author":"Yerlikaya","year":"2022","journal-title":"Expert Systems with Applications"},{"key":"10.1016\/j.neunet.2026.109192_bib0040","doi-asserted-by":"crossref","first-page":"5663","DOI":"10.1109\/TIFS.2025.3574976","article-title":"Modality-specific interactive attack for vision-language pre-training models","volume":"20","author":"Zhang","year":"2025","journal-title":"IEEE Transactions on Information Forensics and Security"},{"issue":"2","key":"10.1016\/j.neunet.2026.109192_bib0041","doi-asserted-by":"crossref","first-page":"2198","DOI":"10.1109\/TDSC.2025.3625576","article-title":"Gradient pruning interactive attack for vision-language pre-training models","volume":"23","author":"Zhang","year":"2025","journal-title":"IEEE Transactions on Dependable and Secure Computing"},{"key":"10.1016\/j.neunet.2026.109192_bib0042","series-title":"Proceedings of the 2023 conference on empirical methods in natural language processing","first-page":"13764","article-title":"Poisoning retrieval corpora by injecting adversarial passages","author":"Zhong","year":"2023"},{"issue":"3","key":"10.1016\/j.neunet.2026.109192_bib0043","doi-asserted-by":"crossref","first-page":"1955","DOI":"10.1109\/COMST.2024.3465447","article-title":"Large language model (LLM) for telecommunications: A comprehensive survey on principles, key techniques, and opportunities","volume":"27","author":"Zhou","year":"2024","journal-title":"IEEE Communications Surveys & Tutorials"},{"key":"10.1016\/j.neunet.2026.109192_bib0044","unstructured":"Zou, A., Wang, Z., Carlini, N., Nasr, M., Kolter, J. Z., & Fredrikson, M. (2023). Universal and transferable adversarial attacks on aligned language models. arXiv preprint arXiv: 2307.15043."},{"key":"10.1016\/j.neunet.2026.109192_bib0045","series-title":"34th USENIX security symposium (USENIX security 25)","first-page":"3827","article-title":"{PoisonedRAG}: Knowledge corruption attacks to {retrieval-augmented} generation of large language models","author":"Zou","year":"2025"}],"container-title":["Neural Networks"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S0893608026006532?httpAccept=text\/xml","content-type":"text\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S0893608026006532?httpAccept=text\/plain","content-type":"text\/plain","content-version":"vor","intended-application":"text-mining"}],"deposited":{"date-parts":[[2026,6,3]],"date-time":"2026-06-03T02:15:36Z","timestamp":1780452936000},"score":1,"resource":{"primary":{"URL":"https:\/\/linkinghub.elsevier.com\/retrieve\/pii\/S0893608026006532"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,11]]},"references-count":45,"alternative-id":["S0893608026006532"],"URL":"https:\/\/doi.org\/10.1016\/j.neunet.2026.109192","relation":{},"ISSN":["0893-6080"],"issn-type":[{"value":"0893-6080","type":"print"}],"subject":[],"published":{"date-parts":[[2026,11]]},"assertion":[{"value":"Elsevier","name":"publisher","label":"This article is maintained by"},{"value":"Fine-grained hierarchical multi-round iterative semantic optimization attack method for RAG systems","name":"articletitle","label":"Article Title"},{"value":"Neural Networks","name":"journaltitle","label":"Journal Title"},{"value":"https:\/\/doi.org\/10.1016\/j.neunet.2026.109192","name":"articlelink","label":"CrossRef DOI link to publisher maintained version"},{"value":"article","name":"content_type","label":"Content Type"},{"value":"\u00a9 2026 Elsevier Ltd. All rights are reserved, including those for text and data mining, AI training, and similar technologies.","name":"copyright","label":"Copyright"}],"article-number":"109192"}}