cs.CRApr 9, 2026

A Survey of Secure Retrieval-Augmented Generation

Authors: Yuming Xu, Mingtao Zhang, Zhuohan Ge, Haoyang Li, Nicole Hu, Yongqi Zhang, Zhiyuan Wen, Jason Chen Zhang, +2 more

Organizations: The Hong Kong Polytechnic University · The Hong Kong University of Science and Technology (Guangzhou)

Abstract

Retrieval-augmented generation (RAG) improves large language models (LLMs) with external knowledge, but this access path creates security risks distinct from inherent prompt-only or parametric-model flaws. We frame secure RAG as securing external knowledge access. We conducted a systematic search and curated 135 works on attacks, defenses, and security evaluation, and organized them with SLOT: a taxonomy along the attack Surface (S) and the corresponding defense Layer (L), with cross-cutting axes Objective (O) and attack-target scope (T). Mapping these studies onto an external knowledge-access pipeline, we expose three mismatches: target mismatch (T2 attacks outpace T2 defenses and evaluation), stage mismatch (S1 attacks outnumber L1 defenses), and signal mismatch (fluent, retrievable, corpus-fitting S1 attacks challenge anomaly-based L2/L3 defenses). Finally, we discuss directions for more realistic targets, surface-complete defense stacks, standardized evaluation, confidentiality, and multimodal and agentic systems, and release the screening process, selected-paper metadata, and machine-readable SLOT labels at https://github.com/TreeAI-Lab/Awesome-RAG-Security.

Explore similar work

CardsList
  1. Security and Privacy in Retrieval-Augmented Generation: Architectures, Threats, Defenses, and Future Directions for Building Trustworthy Systems

    Jun 24, 2026Balamurugan Palanisamy, G S S Chalapathi, Vikas Hassija +1Agentic Retrieval-Augmented Generation SystemsLarge Language Model Safety

  2. BadRAG: Identifying Vulnerabilities in Retrieval Augmented Generation of Large Language Models

    Jun 3, 2024Jiaqi Xue, Mengxin Zheng, Yebowen Hu +3Agentic Retrieval-Augmented Generation SystemsAttacker Large Language Model

  3. TriShieldRAG: A Three-Ring Defense-in-Depth Framework Against Knowledge Corruption in Retrieval-Augmented Generation

    Jul 26, 2026Susil Kumar Mohanty, Rohit Patel, Kosuru Yuvaraj +2Agentic Retrieval-Augmented Generation SystemsPoisoning