{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,16]],"date-time":"2026-07-16T05:16:34Z","timestamp":1784178994690,"version":"3.55.0"},"publisher-location":"New York, NY, USA","reference-count":42,"publisher":"ACM","funder":[{"DOI":"10.13039\/501100018537","name":"National Science and Technology Major Project","doi-asserted-by":"publisher","award":["2023ZD0121502"],"award-info":[{"award-number":["2023ZD0121502"]}],"id":[{"id":"10.13039\/501100018537","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["72404212"],"award-info":[{"award-number":["72404212"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2025,11,19]]},"DOI":"10.1145\/3719027.3765023","type":"proceedings-article","created":{"date-parts":[[2025,11,22]],"date-time":"2025-11-22T23:33:16Z","timestamp":1763854396000},"page":"4109-4123","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":3,"title":["FlippedRAG: Black-Box Opinion Manipulation Adversarial Attacks to Retrieval-Augmented Generation Models"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0009-0002-9618-5099","authenticated-orcid":false,"given":"Zhuo","family":"Chen","sequence":"first","affiliation":[{"name":"Wuhan University, Wuhan, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0006-8799-8425","authenticated-orcid":false,"given":"Yuyang","family":"Gong","sequence":"additional","affiliation":[{"name":"Wuhan University, Wuhan, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-2774-1509","authenticated-orcid":false,"given":"Jiawei","family":"Liu","sequence":"additional","affiliation":[{"name":"Wuhan University, Wuhan, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0004-6304-2766","authenticated-orcid":false,"given":"Miaokun","family":"Chen","sequence":"additional","affiliation":[{"name":"Wuhan University, Wuhan, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-8987-9370","authenticated-orcid":false,"given":"Haotan","family":"Liu","sequence":"additional","affiliation":[{"name":"Wuhan University, Wuhan, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3904-8901","authenticated-orcid":false,"given":"Qikai","family":"Cheng","sequence":"additional","affiliation":[{"name":"Wuhan University, Wuhan, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0831-7371","authenticated-orcid":false,"given":"Fan","family":"Zhang","sequence":"additional","affiliation":[{"name":"Wuhan University, Wuhan, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-0929-7416","authenticated-orcid":false,"given":"Wei","family":"Lu","sequence":"additional","affiliation":[{"name":"Wuhan University, Wuhan, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3477-8323","authenticated-orcid":false,"given":"Xiaozhong","family":"Liu","sequence":"additional","affiliation":[{"name":"Worcester Polytechnic Institute, Worcester, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2025,11,22]]},"reference":[{"key":"e_1_3_2_1_1_1","unstructured":"Kingma DP Ba J Adam et al. 2014. A method for stochastic optimization. arXiv preprint arXiv:1412.6980 1412 6 (2014)."},{"key":"e_1_3_2_1_2_1","first-page":"37068","article-title":"Badprompt: Backdoor attacks on continuous prompts","volume":"35","author":"Cai Xiangrui","year":"2022","unstructured":"Xiangrui Cai, Haidong Xu, Sihan Xu, Ying Zhang, et al. 2022. Badprompt: Backdoor attacks on continuous prompts. Advances in Neural Information Processing Systems 35 (2022), 37068--37080.","journal-title":"Advances in Neural Information Processing Systems"},{"key":"e_1_3_2_1_3_1","doi-asserted-by":"crossref","unstructured":"Nicholas Carlini Matthew Jagielski Christopher A. Choquette-Choo Daniel Paleka Will Pearce Hyrum Anderson Andreas Terzis Kurt Thomas and Florian Tram\u00e8r. 2024. Poisoning Web-Scale Training Datasets is Practical. arXiv:2302.10149 [cs.CR] https:\/\/arxiv.org\/abs\/2302.10149","DOI":"10.1109\/SP54263.2024.00179"},{"key":"e_1_3_2_1_4_1","volume-title":"Phantom: General trigger attacks on retrieval augmented language generation. arXiv preprint arXiv:2405.20485","author":"Chaudhari Harsh","year":"2024","unstructured":"Harsh Chaudhari, Giorgio Severi, John Abascal, Matthew Jagielski, Christopher A Choquette-Choo, Milad Nasr, Cristina Nita-Rotaru, and Alina Oprea. 2024. Phantom: General trigger attacks on retrieval augmented language generation. arXiv preprint arXiv:2405.20485 (2024)."},{"key":"e_1_3_2_1_5_1","unstructured":"Ting Chen Simon Kornblith Mohammad Norouzi and Geoffrey Hinton. 2020. A Simple Framework for Contrastive Learning of Visual Representations. arXiv:2002.05709 [cs.LG] https:\/\/arxiv.org\/abs\/2002.05709"},{"key":"e_1_3_2_1_6_1","volume-title":"Trojanrag: Retrieval-augmented generation can be backdoor driver in large language models. arXiv preprint arXiv:2405.13401","author":"Cheng Pengzhou","year":"2024","unstructured":"Pengzhou Cheng, Yidong Ding, Tianjie Ju, Zongru Wu, Wei Du, Ping Yi, Zhuosheng Zhang, and Gongshen Liu. 2024. Trojanrag: Retrieval-augmented generation can be backdoor driver in large language models. arXiv preprint arXiv:2405.13401 (2024)."},{"key":"e_1_3_2_1_7_1","volume-title":"Typos that Broke the RAG's Back: Genetic Attack on RAG Pipeline by Simulating Documents in the Wild via Low-level Perturbations. arXiv preprint arXiv:2404.13948","author":"Cho Sukmin","year":"2024","unstructured":"Sukmin Cho, Soyeong Jeong, Jeongyeon Seo, Taeho Hwang, and Jong C Park. 2024. Typos that Broke the RAG's Back: Genetic Attack on RAG Pipeline by Simulating Documents in the Wild via Low-level Perturbations. arXiv preprint arXiv:2404.13948 (2024)."},{"key":"e_1_3_2_1_8_1","volume-title":"Jailbreaker: Automated jailbreak across multiple large language model chatbots. arXiv preprint arXiv:2307.08715","author":"Deng Gelei","year":"2023","unstructured":"Gelei Deng, Yi Liu, Yuekang Li, Kailong Wang, Ying Zhang, Zefeng Li, Haoyu Wang, Tianwei Zhang, and Yang Liu. 2023. Jailbreaker: Automated jailbreak across multiple large language model chatbots. arXiv preprint arXiv:2307.08715 (2023)."},{"key":"e_1_3_2_1_9_1","volume-title":"Hotflip: Whitebox adversarial examples for text classification. arXiv preprint arXiv:1712.06751","author":"Ebrahimi Javid","year":"2017","unstructured":"Javid Ebrahimi, Anyi Rao, Daniel Lowd, and Dejing Dou. 2017. Hotflip: Whitebox adversarial examples for text classification. arXiv preprint arXiv:1712.06751 (2017)."},{"key":"e_1_3_2_1_10_1","volume-title":"Robertson","author":"Epstein Robert","year":"2015","unstructured":"Robert Epstein and Ronald E. Robertson. 2015. The search engine manipulation effect (SEME) and its possible impact on the outcomes of elections. Proceedings of the National Academy of Sciences 112, 33 (Aug. 2015), E4512--E4521. doi:10.1073\/ pnas.1419828112 Publisher: Proceedings of the National Academy of Sciences."},{"key":"e_1_3_2_1_11_1","volume-title":"Unsupervised corpus aware language model pre-training for dense passage retrieval. arXiv preprint arXiv:2108.05540","author":"Gao Luyu","year":"2021","unstructured":"Luyu Gao and Jamie Callan. 2021. Unsupervised corpus aware language model pre-training for dense passage retrieval. arXiv preprint arXiv:2108.05540 (2021)."},{"key":"e_1_3_2_1_12_1","volume-title":"Retrieval-augmented generation for large language models: A survey. arXiv preprint arXiv:2312.10997","author":"Gao Yunfan","year":"2023","unstructured":"Yunfan Gao, Yun Xiong, Xinyu Gao, Kangxiang Jia, Jinliu Pan, Yuxi Bi, Yi Dai, Jiawei Sun, and Haofen Wang. 2023. Retrieval-augmented generation for large language models: A survey. arXiv preprint arXiv:2312.10997 (2023)."},{"key":"e_1_3_2_1_13_1","unstructured":"Kaiming He Haoqi Fan Yuxin Wu Saining Xie and Ross Girshick. 2020. Momentum Contrast for Unsupervised Visual Representation Learning. arXiv:1911.05722 [cs.CV] https:\/\/arxiv.org\/abs\/1911.05722"},{"key":"e_1_3_2_1_14_1","volume-title":"Unsupervised dense information retrieval with contrastive learning. arXiv preprint arXiv:2112.09118","author":"Izacard Gautier","year":"2021","unstructured":"Gautier Izacard, Mathilde Caron, Lucas Hosseini, Sebastian Riedel, Piotr Bojanowski, Armand Joulin, and Edouard Grave. 2021. Unsupervised dense information retrieval with contrastive learning. arXiv preprint arXiv:2112.09118 (2021)."},{"key":"e_1_3_2_1_15_1","volume-title":"Baseline defenses for adversarial attacks against aligned language models. arXiv preprint arXiv:2309.00614","author":"Jain Neel","year":"2023","unstructured":"Neel Jain, Avi Schwarzschild, Yuxin Wen, Gowthami Somepalli, John Kirchenbauer, Ping-yeh Chiang, Micah Goldblum, Aniruddha Saha, Jonas Geiping, and Tom Goldstein. 2023. Baseline defenses for adversarial attacks against aligned language models. arXiv preprint arXiv:2309.00614 (2023)."},{"key":"e_1_3_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1145\/3701716.3715313"},{"key":"e_1_3_2_1_17_1","volume-title":"Multi-step jailbreaking privacy attacks on chatgpt. arXiv preprint arXiv:2304.05197","author":"Li Haoran","year":"2023","unstructured":"Haoran Li, Dadi Guo,Wei Fan, Mingshi Xu, Jie Huang, Fanpu Meng, and Yangqiu Song. 2023. Multi-step jailbreaking privacy attacks on chatgpt. arXiv preprint arXiv:2304.05197 (2023)."},{"key":"e_1_3_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP54263.2024.00049"},{"key":"e_1_3_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.1145\/3548606.3560683"},{"key":"e_1_3_2_1_20_1","volume-title":"June","author":"Liu Yi","year":"2023","unstructured":"Yi Liu, Gelei Deng, Yuekang Li, Kailong Wang, Tianwei Zhang, Yepang Liu, Haoyu Wang, Yan Zheng, and Yang Liu. 2023. Prompt Injection attack against LLM-integrated Applications, June 2023. arXiv preprint arXiv:2306.05499 (2023)."},{"key":"e_1_3_2_1_21_1","volume-title":"33rd USENIX Security Symposium (USENIX Security 24)","author":"Liu Yupei","year":"2024","unstructured":"Yupei Liu, Yuqi Jia, Runpeng Geng, Jinyuan Jia, and Neil Zhenqiang Gong. 2024. Formalizing and benchmarking prompt injection attacks and defenses. In 33rd USENIX Security Symposium (USENIX Security 24). 1831--1847."},{"key":"e_1_3_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.1145\/3583780.3614793"},{"key":"e_1_3_2_1_23_1","unstructured":"Zeren Luo Zifan Peng Yule Liu Zhen Sun Mingchen Li Jingyi Zheng and Xinlei He. 2025. Unsafe LLM-Based Search: Quantitative Analysis and Mitigation of Safety Risks in AI Web Search. arXiv:2502.04951 [cs.CR] https:\/\/arxiv.org\/abs\/2502.04951"},{"key":"e_1_3_2_1_24_1","doi-asserted-by":"crossref","unstructured":"Ali Naseh Yuefeng Peng Anshuman Suri Harsh Chaudhari Alina Oprea and Amir Houmansadr. 2025. Riddle Me This! Stealthy Membership Inference for Retrieval-Augmented Generation. arXiv:2502.00306 [cs.CR] https:\/\/arxiv.org\/ abs\/2502.00306","DOI":"10.1145\/3719027.3744840"},{"key":"e_1_3_2_1_25_1","unstructured":"Tri Nguyen Mir Rosenberg Xia Song Jianfeng Gao Saurabh Tiwary Rangan Majumder and Li Deng. 2016. Ms marco: A human-generated machine reading comprehension dataset. (2016)."},{"key":"e_1_3_2_1_26_1","volume-title":"On the risk of misinformation pollution with large language models. arXiv preprint arXiv:2305.13661","author":"Pan Yikang","year":"2023","unstructured":"Yikang Pan, Liangming Pan, Wenhu Chen, Preslav Nakov, Min-Yen Kan, and William Yang Wang. 2023. On the risk of misinformation pollution with large language models. arXiv preprint arXiv:2305.13661 (2023)."},{"key":"e_1_3_2_1_27_1","volume-title":"Machine against the rag: Jamming retrieval-augmented generation with blocker documents. arXiv preprint arXiv:2406.05870","author":"Shafran Avital","year":"2024","unstructured":"Avital Shafran, Roei Schuster, and Vitaly Shmatikov. 2024. Machine against the rag: Jamming retrieval-augmented generation with blocker documents. arXiv preprint arXiv:2406.05870 (2024)."},{"key":"e_1_3_2_1_28_1","volume-title":"Adversarial semantic collisions. arXiv preprint arXiv:2011.04743","author":"Song Congzheng","year":"2020","unstructured":"Congzheng Song, Alexander M Rush, and Vitaly Shmatikov. 2020. Adversarial semantic collisions. arXiv preprint arXiv:2011.04743 (2020)."},{"key":"e_1_3_2_1_29_1","volume-title":"RbFT: Robust Fine-tuning for Retrieval-Augmented Generation against Retrieval Defects. arXiv preprint arXiv:2501.18365","author":"Tu Yiteng","year":"2025","unstructured":"Yiteng Tu, Weihang Su, Yujia Zhou, Yiqun Liu, and Qingyao Ai. 2025. RbFT: Robust Fine-tuning for Retrieval-Augmented Generation against Retrieval Defects. arXiv preprint arXiv:2501.18365 (2025)."},{"key":"e_1_3_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.1145\/3576923"},{"key":"e_1_3_2_1_31_1","volume-title":"Certifiably Robust RAG against Retrieval Corruption. arXiv preprint arXiv:2405.15556","author":"Xiang Chong","year":"2024","unstructured":"Chong Xiang, TongWu, Zexuan Zhong, DavidWagner, Danqi Chen, and Prateek Mittal. 2024. Certifiably Robust RAG against Retrieval Corruption. arXiv preprint arXiv:2405.15556 (2024)."},{"key":"e_1_3_2_1_32_1","volume-title":"Approximate nearest neighbor negative contrastive learning for dense text retrieval. arXiv preprint arXiv:2007.00808","author":"Xiong Lee","year":"2020","unstructured":"Lee Xiong, Chenyan Xiong, Ye Li, Kwok-Fung Tang, Jialin Liu, Paul Bennett, Junaid Ahmed, and Arnold Overwijk. 2020. Approximate nearest neighbor negative contrastive learning for dense text retrieval. arXiv preprint arXiv:2007.00808 (2020)."},{"key":"e_1_3_2_1_33_1","volume-title":"BadRAG: Identifying Vulnerabilities in Retrieval Augmented Generation of Large Language Models. arXiv preprint arXiv:2406.00083","author":"Xue Jiaqi","year":"2024","unstructured":"Jiaqi Xue, Mengxin Zheng, Yebowen Hu, Fei Liu, Xun Chen, and Qian Lou. 2024. BadRAG: Identifying Vulnerabilities in Retrieval Augmented Generation of Large Language Models. arXiv preprint arXiv:2406.00083 (2024)."},{"key":"e_1_3_2_1_34_1","first-page":"107","article-title":"Homogenization Dilemma:Concept Analysis and Theoretical Framework Construction of Information Cocoons","volume":"49","author":"Yue Zhang","year":"2023","unstructured":"Zhang Yue, ZHUANG Bichen, LI Qingyu, and ZHU Qinghua. 2023. Homogenization Dilemma:Concept Analysis and Theoretical Framework Construction of Information Cocoons. Journal of Library Science in China 49, 3 (2023), 107--122.","journal-title":"Journal of Library Science in China"},{"key":"e_1_3_2_1_35_1","doi-asserted-by":"crossref","unstructured":"Shenglai Zeng Jiankun Zhang Pengfei He Yue Xing Yiding Liu Han Xu Jie Ren Shuaiqiang Wang Dawei Yin Yi Chang and Jiliang Tang. 2024. The Good and The Bad: Exploring Privacy Issues in Retrieval-Augmented Generation (RAG). arXiv:2402.16893 [cs.CR] https:\/\/arxiv.org\/abs\/2402.16893","DOI":"10.18653\/v1\/2024.findings-acl.267"},{"key":"e_1_3_2_1_36_1","volume-title":"Human-Imperceptible Retrieval Poisoning Attacks in LLM-Powered Applications. In Companion Proceedings of the 32nd ACM International Conference on the Foundations of Software Engineering. 502--506","author":"Zhang Quan","year":"2024","unstructured":"Quan Zhang, Binqi Zeng, Chijin Zhou, Gwihwan Go, Heyuan Shi, and Yu Jiang. 2024. Human-Imperceptible Retrieval Poisoning Attacks in LLM-Powered Applications. In Companion Proceedings of the 32nd ACM International Conference on the Foundations of Software Engineering. 502--506."},{"key":"e_1_3_2_1_37_1","volume-title":"Retrieval-augmented generation for ai-generated content: A survey. arXiv preprint arXiv:2402.19473","author":"Zhao Penghao","year":"2024","unstructured":"Penghao Zhao, Hailin Zhang, Qinhan Yu, Zhengren Wang, Yunteng Geng, Fangcheng Fu, Ling Yang,Wentao Zhang, and Bin Cui. 2024. Retrieval-augmented generation for ai-generated content: A survey. arXiv preprint arXiv:2402.19473 (2024)."},{"key":"e_1_3_2_1_38_1","volume-title":"Weak-to-strong jailbreaking on large language models. arXiv preprint arXiv:2401.17256","author":"Zhao Xuandong","year":"2024","unstructured":"Xuandong Zhao, Xianjun Yang, Tianyu Pang, Chao Du, Lei Li, Yu-Xiang Wang, and William Yang Wang. 2024. Weak-to-strong jailbreaking on large language models. arXiv preprint arXiv:2401.17256 (2024)."},{"key":"e_1_3_2_1_39_1","volume-title":"Poisoning retrieval corpora by injecting adversarial passages. arXiv preprint arXiv:2310.19156","author":"Zhong Zexuan","year":"2023","unstructured":"Zexuan Zhong, Ziqing Huang, Alexander Wettig, and Danqi Chen. 2023. Poisoning retrieval corpora by injecting adversarial passages. arXiv preprint arXiv:2310.19156 (2023)."},{"key":"e_1_3_2_1_40_1","volume-title":"In Proceedings of the 15th ACM SIGKDD International Conference on Knowledge Discovery and Data Mining, KDD","volume":"9","author":"Zhou Bin","year":"2009","unstructured":"Bin Zhou and Jian Pei. 2009. OSD: An online web spam detection system. In In Proceedings of the 15th ACM SIGKDD International Conference on Knowledge Discovery and Data Mining, KDD, Vol. 9."},{"key":"e_1_3_2_1_41_1","doi-asserted-by":"crossref","unstructured":"Huichi Zhou Kin-Hei Lee Zhonghao Zhan Yue Chen Zhenhao Li Zhaoyang Wang Hamed Haddadi and Emine Yilmaz. 2025. TrustRAG: Enhancing Robustness and Trustworthiness in Retrieval-Augmented Generation. arXiv:2501.00879 [cs.CL] https:\/\/arxiv.org\/abs\/2501.00879","DOI":"10.32388\/Z4DWHQ"},{"key":"e_1_3_2_1_42_1","volume-title":"Poisonedrag: Knowledge poisoning attacks to retrieval-augmented generation of large language models. arXiv preprint arXiv:2402.07867","author":"Zou Wei","year":"2024","unstructured":"Wei Zou, Runpeng Geng, Binghui Wang, and Jinyuan Jia. 2024. Poisonedrag: Knowledge poisoning attacks to retrieval-augmented generation of large language models. arXiv preprint arXiv:2402.07867 (2024)."}],"event":{"name":"CCS '25: ACM SIGSAC Conference on Computer and Communications Security","location":"Taipei Taiwan","acronym":"CCS '25","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"]},"container-title":["Proceedings of the 2025 ACM SIGSAC Conference on Computer and Communications Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3719027.3765023","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,12,22]],"date-time":"2025-12-22T22:19:22Z","timestamp":1766441962000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3719027.3765023"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,11,19]]},"references-count":42,"alternative-id":["10.1145\/3719027.3765023","10.1145\/3719027"],"URL":"https:\/\/doi.org\/10.1145\/3719027.3765023","relation":{},"subject":[],"published":{"date-parts":[[2025,11,19]]},"assertion":[{"value":"2025-11-22","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}