RAG-Pull: Turning Retrieval into a Code-Injection Channel via Invisible Unicode Perturbations

📰 ArXiv cs.AI

Learn how RAG-Pull attacks inject malicious code into LLMs via invisible Unicode perturbations, compromising model reliability and trustworthiness

advanced Published 25 May 2026
Action Steps
  1. Identify potential vulnerabilities in RAG models using Unicode perturbations
  2. Analyze query and external code repositories for hidden UTF characters
  3. Develop and implement detection methods for RAG-Pull attacks
  4. Test and evaluate the effectiveness of RAG-Pull attack detection
  5. Apply security patches and updates to prevent RAG-Pull attacks
Who Needs to Know This

AI researchers, developers, and security experts can benefit from understanding RAG-Pull attacks to improve LLM security and robustness

Key Insight

💡 RAG-Pull attacks compromise LLM reliability and trustworthiness by injecting malicious code via invisible Unicode perturbations

Share This
🚨 New RAG-Pull attack injects malicious code into LLMs via invisible Unicode perturbations 🚨

Key Takeaways

Learn how RAG-Pull attacks inject malicious code into LLMs via invisible Unicode perturbations, compromising model reliability and trustworthiness

Full Article

Title: RAG-Pull: Turning Retrieval into a Code-Injection Channel via Invisible Unicode Perturbations

Abstract:
arXiv:2510.11195v2 Announce Type: replace-cross Abstract: Retrieval-Augmented Generation (RAG) increases the reliability and trustworthiness of the LLM response and reduces hallucination by eliminating the need for model retraining. It does so by adding external data into the LLM's context. We develop a new class of black-box attack, RAG-Pull, that inserts hidden UTF characters into queries or external code repositories, redirecting retrieval toward malicious code, thereby breaking the models' s
Read full paper → ← Back to Reads

Related Videos

5 Levels of AI Agents - From Simple LLM Calls to Multi-Agent Systems
5 Levels of AI Agents - From Simple LLM Calls to Multi-Agent Systems
Dave Ebbelaar (LLM Eng)
Off-Page Topical Map: Why Third-Party Corroboration Improves LLM Visibility (Karl ft James)
Off-Page Topical Map: Why Third-Party Corroboration Improves LLM Visibility (Karl ft James)
James Dooley
Why AI Query Fan Out Has Online Reputation Management 10x Harder? (Karl Hudson ft James Dooley)
Why AI Query Fan Out Has Online Reputation Management 10x Harder? (Karl Hudson ft James Dooley)
James Dooley
AI Resume - Why Has ORM Become More Important? (Karl Hudson ft James Dooley)
AI Resume - Why Has ORM Become More Important? (Karl Hudson ft James Dooley)
James Dooley
AI Reputation Tree - Getting The LLMs To Be Your 24/7 Sales Engine (Karl Hudson ft James Dooley)
AI Reputation Tree - Getting The LLMs To Be Your 24/7 Sales Engine (Karl Hudson ft James Dooley)
James Dooley
Why All Brands Should Track LLMs and Improve Sentiment in AI Overviews (Karl Hudson ft James Dooley)
Why All Brands Should Track LLMs and Improve Sentiment in AI Overviews (Karl Hudson ft James Dooley)
James Dooley