AIIC AI Intelligence Centre

SOURCE-LINKED INTELLIGENCE

CodePoisonRAG: Knowledge Poisoning Attacks on Retrieval-Augmented Code Generation

arXiv · AI, language, vision and robotics · article · Sep 2, 2026 · UTC

Retrieval-Augmented Code Generation (RACG) improves LLM-based software development by retrieving external code artifacts, documentation, and patches, and incorporating them into the generation context. This reliance on external knowledge introduces a critical trust boundary: poisoned artifacts can influence generated code without modifying the underlying LLM. Prior work shows that selecting existing vulnerable examples can increase the general vulnerability rate of RACG outputs, but leaves open whether a black-box attacker can construct a single task-matched artifact that propagates an attacke

Read original source ↗ Open in workspace

recordType
paper
region
Global

Evidence & attribution

First collected: 2026-09-21T05:32:15.665Z. This is not the publication date.