TY - GEN
T1 - Combating Knowledge Corruption in Agent Systems
T2 - 35th ACM Web Conference, WWW 2026
AU - Wang, Zhaoqi
AU - He, Daqing
AU - Zhang, Zijian
AU - Liu, Ye
AU - Liu, Jiamou
AU - Zeng, Zhirui
AU - Qin, Zhan
AU - Li, Zhen
AU - Li, Xin
AU - Yao, Hongwei
AU - An, Jincheng
AU - Liu, Yong
AU - Li, Yi
AU - Sun, Qi
AU - Liu, Xiulei
AU - Zhu, Liehuang
N1 - Publisher Copyright:
© 2026 Owner/Author.
PY - 2026/4/12
Y1 - 2026/4/12
N2 - While retrieval-augmented generation systems partially address the hallucination issues in large language models, it also introduces new vulnerabilities to knowledge corruption attacks. Adversaries exploit these vulnerabilities by poisoning documents provided by RAG system to manipulate LLM outputs. To counter this threat, we propose SecureCollaRAG, a Byzantine-tolerant collaborative RAG framework leveraging Multi-source Knowledge Validation Mechanism. Our approach enables agent system to securely verify document provenance through dynamic GNN-based credibility scoring, effectively preventing stealthy knowledge corruption attacks while preserving essential domain knowledge integrity. Through extensive evaluations and formal analysis, we demonstrate that SecureCollaRAG maintains robustness against attackers under non-IID data distributions.
AB - While retrieval-augmented generation systems partially address the hallucination issues in large language models, it also introduces new vulnerabilities to knowledge corruption attacks. Adversaries exploit these vulnerabilities by poisoning documents provided by RAG system to manipulate LLM outputs. To counter this threat, we propose SecureCollaRAG, a Byzantine-tolerant collaborative RAG framework leveraging Multi-source Knowledge Validation Mechanism. Our approach enables agent system to securely verify document provenance through dynamic GNN-based credibility scoring, effectively preventing stealthy knowledge corruption attacks while preserving essential domain knowledge integrity. Through extensive evaluations and formal analysis, we demonstrate that SecureCollaRAG maintains robustness against attackers under non-IID data distributions.
KW - graph neural network
KW - knowledge corruption attacks
KW - large language model
KW - retrieval-augmented generation
KW - securecollarag
UR - https://www.scopus.com/pages/publications/105038563538
U2 - 10.1145/3774904.3792200
DO - 10.1145/3774904.3792200
M3 - Conference contribution
AN - SCOPUS:105038563538
T3 - WWW 2026 - Proceedings of the ACM Web Conference 2026
SP - 2661
EP - 2672
BT - WWW 2026 - Proceedings of the ACM Web Conference 2026
PB - Association for Computing Machinery, Inc
Y2 - 29 June 2026 through 3 July 2026
ER -