T3Attacking AI Systems
Attacking RAG Pipelines
Retrieval-augmented generation widens the attack surface, because every document in the store is untrusted input. Indirect injection, retrieval poisoning, and embedding-space attacks.
Foundational2 min readfoundation streamUpdated Fri Jul 31 2026 00:00:00 GMT+0000 (Coordinated Universal Time)
Learning objectives
- Trace how a poisoned document reaches the model in a RAG flow
- Explain retrieval poisoning and why relevance ranking helps the attacker
- Describe an embedding-space attack at a conceptual level
Academy subscription
Subscribe to unlock this module
This module is part of the StrikeOps Academy subscription. Unlock every paid module, with hands-on labs and knowledge checks.
- Every paid module across all tracks
- Hands-on labs and knowledge checks
- New content as it ships
$59/ month · or $590 / year
The Reference library and Foundation starters are free to read now.