[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-83803-en":3,"doc-seo-83803-105":30,"detail-sidebar-cat-0-en-105":92},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":21,"is_downloadable":21,"audit_status":21,"page_count":22,"language":23,"language_code":24,"site_id":25,"html_lang":24,"table_of_contents":26,"faqs":27,"seo_title":13,"seo_description":14,"update_tm":28,"read_time":29},83803,5909877438554,"Maeve","https://ap-avatar.wpscdn.com/avatar/5600025385ad2bf12a7?_k=1778553567797529272",8,"Research & Report","Knowledge Base Poisoning Attacks and Defense for Policy-Aware LLM-RAG Framework","Policy-Aware Large Language Model Retrieval-Augmented Generation (PA-LLM-RAG) grounds LLM decisions in structured operational policies, but adversarial robustness for such edge-deployed frameworks is not established. This paper delivers a comprehensive adversarial evaluation and introduces Query-Agnostic Semantic Retrieval Poisoning, which injects semantically crafted rules into an IoBT knowledge base to obtain high retrieval ranking across operator query types without using runtime prompts. The attack yields 85% LLM context corruption from a single injected rule and remains stable up to 25% poisoning. A dual-detector CLD-KB defense combines One-Class SVM boundary detection with Member-Based Category Spread analysis over a three-category policy taxonomy to preserve knowledge.","Knowledge Base Poisoning Attacks and Defense for Policy-Aware LLM-RAG Framework  \nOm Solanki∗ , Lopamudra Praharaj†, Deepti Gupta‡, Maanak Gupta∗  \n∗ Department of Computer Science, Tennessee Tech University, TN, USA.  \n†Dept. of Mathematics & Computer Science, University of North Carolina at Pembroke, NC, USA.‡Dept. of Computer Information Systems, Texas A&M University -Central Texas, TX, USA.  \nCorresponding [e-mail: mgupta@tntech.edu](e-mail: mgupta@tntech.edu)  \narXiv :2607 .04379v 1 [ cs .CR] 5 Jul 2026  \nAbstract—Policy-Aware Large Language Model RetrievalAugmented Generation (PA-LLM-RAG) demonstrated that edgedeployed retrieval-augmented generation can ground LLM decisions in structured operational policies. However, the security of such frameworks under adversarial conditions remains unexplored. This paper presents a comprehensive adversarial evaluation of PA-LLM-RAG and introduces a novel attack along with an effective defense mechanism targeting the knowledge-base retrieval layer. We propose Query-Agnostic Semantic Retrieval Poisoning, which injects semantically crafted rules into the IoBT knowledge base that achieve high retrieval ranking across all operator query types without requiring knowledge of runtime prompts. The attack achieves 85% LLM context corruption from a single injected rule (1.6% poisoning rate) and saturates at 2.65 poisoned rules per LLM context at 7.7% poisoning, with effectiveness remaining constant across all evaluated poisoning rates up to 25%, demonstrating that even minimal knowledge base compromise is sufficient to corrupt mission decisions.  \nFurther, to counter this threat, we propose Cyber-Layered Defense for Knowledge Base (CLD-KB), a dual-detector anomaly detection framework combining One-Class SVM boundary detection with a novel Member-Based Category Spread analysis that exploits the three-category policy taxonomy (Workflow, Rules of Engagement, Capability) to identify the cross-category embedding signature unique to poisoned rules. CLD-KB significantly outperforms five baseline methods including DBSCAN, LOF, KMeans, Isolation Forest, and One-Class SVM in both poisoning detection and knowledge preservation. System evaluation across poisoning rates from 1.6% to 25% confirms 100% context integrity with only 7ms computational overhead per mission, establishing CLD-KB as an effective and edge-deployable defense for LLM-driven for Internet of Battlefield Things (IoBT) mission control.  \nIndex Terms—Retrieval-Augmented Generation, Knowledge Base Poisoning, CLD-KB, Adversarial Attacks, Large Language Models, Policy Enforcement, Internet of Battlefield Things  \nI. INTRODUCTION  \nThe Internet of Battlefield Things (IoBT) enables heterogeneous cyber-physical assets such as unmanned aerial/ground vehicles, robotic platforms, and distributed sensors to operate collaboratively in dynamic and adversarial environments [1] . These systems must meet strict latency, reliability, and safety constraints while supporting mission-critical objectives. As IoBT networks grow in scale and complexity, traditional command-and-control approaches based on static rules and predefined workflows struggle to provide the adaptability required for real-time operations [2], [3] .  \nReal-world incidents demonstrate how adversaries can exploit vulnerabilities in mission-critical infrastructure [4] . In autonomous systems, such vulnerabilities extend beyond network intrusion to the application layer itself, where compromised control logic or manipulated decision context can cause autonomous agents to take physically harmful actions without triggering traditional security defenses. As Large Language Model (LLM)-based orchestration frameworks are increasingly considered for mission-critical deployments, their adversarial attack surfaces must be characterized before operational adoption. Retrieval-Augmented Generation (RAG) addresses this gap by grounding LLM decisions in a structured policy knowledge base containing operation","cbCaitQaiFD1DKCd","https://ap.wps.com/l/cbCaitQaiFD1DKCd","pdf",876614,5,1,9,"English","en",105,"# Introduction\n## IoBT and policy-driven LLM orchestration\n## RAG and the knowledge-base integrity problem\n# Proposed Attack and Defense\n## Query-Agnostic Semantic Retrieval Poisoning\n## CLD-KB dual-detector defense","[{\"question\":\"What security gap does the paper address for PA-LLM-RAG frameworks?\",\"answer\":\"It addresses the lack of study on how PA-LLM-RAG behaves under adversarial conditions, specifically when the retrieval layer’s knowledge base can be compromised.\"},{\"question\":\"How does Query-Agnostic Semantic Retrieval Poisoning work?\",\"answer\":\"It injects semantically crafted rules into the IoBT knowledge base so they achieve high retrieval ranking across different operator query types, without requiring access to runtime prompts.\"},{\"question\":\"What is CLD-KB and how does it detect poisoned knowledge?\",\"answer\":\"CLD-KB uses a dual-detector approach: One-Class SVM for boundary detection and Member-Based Category Spread analysis that exploits a three-category policy taxonomy to identify the embedding signature of poisoned rules.\"}]",1784190518,23,{"code":4,"msg":31,"data":32},"ok",{"site_id":25,"language":24,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":87,"head_meta":89,"extra_data":91,"updated_unix":28},"knowledge-base-poisoning-attacks-and-defense-for-policy-aware-llm-rag-framework","",{"@graph":36,"@context":86},[37,54,69],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":21},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":50},"https://docshare.wps.com/document/research-report/",3,{"item":52,"name":13,"@type":43,"position":53},"https://docshare.wps.com/document/knowledge-base-poisoning-attacks-and-defense-for-policy-aware-llm-rag-framework/83803/",4,{"url":52,"name":13,"@type":55,"author":56,"headline":13,"publisher":58,"fileFormat":61,"inLanguage":24,"description":14,"dateModified":62,"datePublished":63,"encodingFormat":61,"isAccessibleForFree":64,"interactionStatistic":65},"DigitalDocument",{"name":9,"@type":57},"Person",{"url":41,"name":59,"@type":60},"DocShare","Organization","application/pdf","2026-07-24","2026-07-16",true,{"@type":66,"interactionType":67,"userInteractionCount":20},"InteractionCounter",{"@type":68},"ViewAction",{"@type":70,"mainEntity":71},"FAQPage",[72,78,82],{"name":73,"@type":74,"acceptedAnswer":75},"What security gap does the paper address for PA-LLM-RAG frameworks?","Question",{"text":76,"@type":77},"It addresses the lack of study on how PA-LLM-RAG behaves under adversarial conditions, specifically when the retrieval layer’s knowledge base can be compromised.","Answer",{"name":79,"@type":74,"acceptedAnswer":80},"How does Query-Agnostic Semantic Retrieval Poisoning work?",{"text":81,"@type":77},"It injects semantically crafted rules into the IoBT knowledge base so they achieve high retrieval ranking across different operator query types, without requiring access to runtime prompts.",{"name":83,"@type":74,"acceptedAnswer":84},"What is CLD-KB and how does it detect poisoned knowledge?",{"text":85,"@type":77},"CLD-KB uses a dual-detector approach: One-Class SVM for boundary detection and Member-Based Category Spread analysis that exploits a three-category policy taxonomy to identify the embedding signature of poisoned rules.","https://schema.org",{"og:url":52,"og:type":88,"og:title":13,"og:site_name":59,"og:description":14},"article",{"robots":90,"canonical":52},"index,follow",{"doc_id":7,"site_id":25},{"code":4,"msg":5,"data":93},[94,98,102,106,110,115,120,123,127,130,134],{"id":21,"doc_module":4,"doc_module_name":46,"category_name":95,"show_sort_weight":96,"slug":97},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":99,"show_sort_weight":100,"slug":101},"Literature",80,"literature",{"id":53,"doc_module":4,"doc_module_name":46,"category_name":103,"show_sort_weight":104,"slug":105},"Exam",70,"exam",{"id":20,"doc_module":4,"doc_module_name":46,"category_name":107,"show_sort_weight":108,"slug":109},"Comic",60,"comic",{"id":111,"doc_module":4,"doc_module_name":46,"category_name":112,"show_sort_weight":113,"slug":114},6,"Technology",50,"technology",{"id":116,"doc_module":4,"doc_module_name":46,"category_name":117,"show_sort_weight":118,"slug":119},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":121,"slug":122},30,"research-report",{"id":22,"doc_module":4,"doc_module_name":46,"category_name":124,"show_sort_weight":125,"slug":126},"Religion & Spirituality",20,"religion-spirituality",{"id":125,"doc_module":4,"doc_module_name":46,"category_name":128,"show_sort_weight":125,"slug":129},"World Cup","world-cup",{"id":131,"doc_module":4,"doc_module_name":46,"category_name":132,"show_sort_weight":131,"slug":133},10,"Lifestyle","lifestyle",{"id":135,"doc_module":4,"doc_module_name":46,"category_name":136,"show_sort_weight":20,"slug":137},19,"General","general"]