TL;DR
This paper exposes vulnerabilities in multimodal retrieval-augmented generation models by demonstrating how targeted and broad knowledge poisoning attacks can significantly disrupt their factual accuracy and reasoning capabilities.
Contribution
The paper introduces MM-PoisonRAG, the first systematic framework for designing knowledge poisoning attacks on multimodal RAG models, including localized and globalized strategies.
Findings
Localized Poisoning Attack achieves up to 56% success rate.
Globalized Poisoning Attack can reduce model accuracy to 0%.
Attacks are effective across different models and access settings.
Abstract
Multimodal large language models with Retrieval Augmented Generation (RAG) have significantly advanced tasks such as multimodal question answering by grounding responses in external text and images. This grounding improves factuality, reduces hallucination, and extends reasoning beyond parametric knowledge. However, this reliance on external knowledge poses a critical yet underexplored safety risk: knowledge poisoning attacks, where adversaries deliberately inject adversarial multimodal content into external knowledge bases to steer model toward generating incorrect or even harmful responses. To expose such vulnerabilities, we propose MM-PoisonRAG, the first framework to systematically design knowledge poisoning in multimodal RAG. We introduce two complementary attack strategies: Localized Poisoning Attack (LPA), which implants targeted multimodal misinformation to manipulate specific…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Code & Models
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
MethodsAttention Is All You Need · Weight Decay · Dense Connections · Attention Dropout · Linear Layer · Layer Normalization · Byte Pair Encoding · Residual Connection · Refunds@Expedia|||How do I get a full refund from Expedia? · Linear Warmup With Linear Decay
