Cover image

When Grounding Becomes the Attack Surface: RAG Under Poisoned Evidence

TL;DR for operators An enterprise assistant can retrieve three passages that all look relevant and still answer from a corrupted evidence base. Once the generator has been instructed to rely on retrieved material, the integrity of that material becomes part of the system’s reliability boundary. Iliano Fasolino’s 2026 experiment1 measures this directly. In a small local RAG setup, poisoned-answer accuracy fell from 69.4% in the nominal 0-of-3 corruption condition to 43.5% when all three retrieved passages were corrupted. The rate of runs where a clean-context answer was correct but its poisoned counterpart was not rose from 9.5% to 34.0%. ...

September 30, 2026 · 7 min · Zelina