[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-82895-en":3,"doc-seo-82895-105":30,"detail-sidebar-cat-0-en-105":91},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":21,"is_downloadable":21,"audit_status":21,"page_count":22,"language":23,"language_code":24,"site_id":25,"html_lang":24,"table_of_contents":26,"faqs":27,"seo_title":13,"seo_description":14,"update_tm":28,"read_time":29},82895,8796095461564,"Liam","https://ap-avatar.wpscdn.com/davatar_155a257f0dc6eb9ab79c44ca47cae57d",8,"Research & Report","MIRAGE：Defending Long-Form RAG Against Misinformation Pollution","Retrieval-Augmented Generation (RAG) grounds LLMs in external evidence, but real retrieval pipelines can be polluted with semantically relevant misinformation, misleading framings, or fabrications that shift answers with high confidence. MIRAGE offers a training-free, model-agnostic defense for long-form RAG by building an NLI-based cross-document claim graph and using a Defended-Claims Gate to condition generation on verified multi-source claims or to block retrieval and fall back to parametric generation. A minimal-edit protocol injects four perturbation families to enable clean, mixed, and fully polluted evaluations. Experiments on four long-form QA benchmarks show consistent factuality restoration and gains over prior robust-RAG methods.","MIRAGE: Defending Long-Form RAG Against Misinformation Pollution  \nSaadeldine Eletter 1 , Ruihong Zeng 1 , Yuxia Wang2 , Maxim Panov 1 , Aleksandr Rubashevskii 1 , and Preslav Nakov 1  \n1Mohamed bin Zayed University of Artificial Intelligence (MBZUAI)  \n2INSAIT, Sofia University “St. Kliment Ohridski”  \n{[saadeldine.eletter}@mbzuai.ac.ae](saadeldine.eletter}@mbzuai.ac.ae)  \narXiv :2607 .05069v 1 [ cs .CL] 6 Jul 2026  \nAbstract  \nRetrieval-Augmented Generation (RAG) improves factuality by grounding LLMs in external evidence, but real-world retrieval is often polluted: semantically relevant passages may contain subtle misinformation, misleading framings, or fabrications. We introduce MIRAGE, a training-free, model-agnostic defense for long-form RAG. MIRAGE builds an NLIbased cross-document claim graph and applies a Defended-Claims Gate to either condition generation on a consistent, multi-source supported subset or to block retrieval and answer parametrically. We also release a minimal-edit pollution protocol spanning four perturbation families (Unambiguous, Conflicting, Misleading, Fabricated) to construct matched clean, mixed, and fully polluted evaluation regimes.  \nAcross four long-form QA benchmarks and multiple commercial and open-weight LLMs, pollution severely degrades vanilla RAG, while MIRAGE consistently restores factuality under mixed and fully polluted evidence and outperforms prior robust-RAG methods. Our implementation and datasets are available at [https://github.com/SaadElDine/MIRAGE](https://github.com/SaadElDine/MIRAGE).  \n1 Introduction  \nLong-form Question Answering relies heavily on Retrieval-Augmented Generation (RAG) to generate comprehensive and factual responses (Wei et al., 2024 ; Chen et al., 2025) . Although RAG mitigates“hallucinations”, it is prone to errors due to unreliable retrieval passages (Yoran et al., 2024) . In practice, knowledge bases and web indices are noisy environments, containing not just irrelevant documents, but polluted evidence, which are plausible sounding texts that contain subtle fabrications, entity swaps, or incorrect temporal attributions (Pan et al., 2023 ; Zeng et al., 2025) .  \nCurrent LLMs exhibit a “sycophancy” bias towards retrieved context, often propagating these  \nTop-k  \nClean (Wiki)  \nPOLLUTED  \n(Fake)  \nClean (News)  \nFigure 1: Polluted RAG problem. A retriever returns a mix of clean and polluted passages. Even a single highscoring polluted document can steer the LLM toward a confident but incorrect answer.  \nerrors into the final answer with high confidence (Perez et al., 2023) . Figure 1 demonstrates atypical failure mode: a single high scoring polluted document can steer the model away from established facts, resulting in generated answers that are relevant but factually incorrect. We argue that robustness in RAG requires moving beyond simple context concatenation toward active evidence adjudication.  \nTo solve the aforementioned problem, we introduce MIRAGE, a methodology that defends the generation of RAG models against retrieval pollution by enforcing the verification of the corresponding claims. Our core insight is that correct claims are often repetitive and consistent across diverse sources, whereas statements containing misinformation are contradictory to each other. MIRAGE utilizes this observation via a two-stage process. First, it extracts sentence-level claims from retrieved passages and builds a support and contradiction graph using Natural Language Inference (NLI) . By analyzing the graph’s internal inconsistency, MIRAGE decides whether to proceed  \nwith RAG or fallback to the model’s parametric knowledge. Second, for the generated response, we condition generation on a structured set of verified claims and instruct the model to ground its output in this evidence.  \nWe rigorously evaluate MIRAGE on four longform datasets using a new pollution protocol that injects controllable corruptions (e.g., Unambiguous, Conflicting, Misleading) . Our result","cbCaibS3zumhjVh7","https://ap.wps.com/l/cbCaibS3zumhjVh7","pdf",2428864,3,1,19,"English","en",105,"# Abstract\n# Introduction\n# Related Work","[{\"question\":\"What problem does MIRAGE address in long-form RAG?\",\"answer\":\"MIRAGE addresses retrieval pollution, where semantically relevant passages contain subtle misinformation, misleading framing, or fabrications that can steer the LLM to confident but incorrect answers.\"},{\"question\":\"How does MIRAGE defend RAG against polluted evidence?\",\"answer\":\"MIRAGE extracts sentence-level claims from retrieved passages, builds a Natural Language Inference (NLI) support/contradiction graph, and uses a Defended-Claims Gate to either condition generation on a verified consistent subset or block retrieval and fall back to parametric knowledge.\"},{\"question\":\"How is the evaluation pollution protocol constructed and what corruption families are used?\",\"answer\":\"MIRAGE releases a minimal-edit pollution protocol that injects controllable perturbations from four families: Unambiguous, Conflicting, Misleading, and Fabricated, enabling matched clean, mixed, and fully polluted evaluation regimes.\"}]",1784183769,48,{"code":4,"msg":31,"data":32},"ok",{"site_id":25,"language":24,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":86,"head_meta":88,"extra_data":90,"updated_unix":28},"mirage-defending-long-form-rag-against-misinformation-pollution","",{"@graph":36,"@context":85},[37,53,68],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,50],{"item":41,"name":42,"@type":43,"position":21},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":20},"https://docshare.wps.com/document/research-report/",{"item":51,"name":13,"@type":43,"position":52},"https://docshare.wps.com/document/mirage-defending-long-form-rag-against-misinformation-pollution/82895/",4,{"url":51,"name":13,"@type":54,"author":55,"headline":13,"publisher":57,"fileFormat":60,"inLanguage":24,"description":14,"dateModified":61,"datePublished":62,"encodingFormat":60,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":56},"Person",{"url":41,"name":58,"@type":59},"DocShare","Organization","application/pdf","2026-07-24","2026-07-16",true,{"@type":65,"interactionType":66,"userInteractionCount":20},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81],{"name":72,"@type":73,"acceptedAnswer":74},"What problem does MIRAGE address in long-form RAG?","Question",{"text":75,"@type":76},"MIRAGE addresses retrieval pollution, where semantically relevant passages contain subtle misinformation, misleading framing, or fabrications that can steer the LLM to confident but incorrect answers.","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"How does MIRAGE defend RAG against polluted evidence?",{"text":80,"@type":76},"MIRAGE extracts sentence-level claims from retrieved passages, builds a Natural Language Inference (NLI) support/contradiction graph, and uses a Defended-Claims Gate to either condition generation on a verified consistent subset or block retrieval and fall back to parametric knowledge.",{"name":82,"@type":73,"acceptedAnswer":83},"How is the evaluation pollution protocol constructed and what corruption families are used?",{"text":84,"@type":76},"MIRAGE releases a minimal-edit pollution protocol that injects controllable perturbations from four families: Unambiguous, Conflicting, Misleading, and Fabricated, enabling matched clean, mixed, and fully polluted evaluation regimes.","https://schema.org",{"og:url":51,"og:type":87,"og:title":13,"og:site_name":58,"og:description":14},"article",{"robots":89,"canonical":51},"index,follow",{"doc_id":7,"site_id":25},{"code":4,"msg":5,"data":92},[93,97,101,105,110,115,120,123,128,131,135],{"id":21,"doc_module":4,"doc_module_name":46,"category_name":94,"show_sort_weight":95,"slug":96},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":98,"show_sort_weight":99,"slug":100},"Literature",80,"literature",{"id":52,"doc_module":4,"doc_module_name":46,"category_name":102,"show_sort_weight":103,"slug":104},"Exam",70,"exam",{"id":106,"doc_module":4,"doc_module_name":46,"category_name":107,"show_sort_weight":108,"slug":109},5,"Comic",60,"comic",{"id":111,"doc_module":4,"doc_module_name":46,"category_name":112,"show_sort_weight":113,"slug":114},6,"Technology",50,"technology",{"id":116,"doc_module":4,"doc_module_name":46,"category_name":117,"show_sort_weight":118,"slug":119},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":121,"slug":122},30,"research-report",{"id":124,"doc_module":4,"doc_module_name":46,"category_name":125,"show_sort_weight":126,"slug":127},9,"Religion & Spirituality",20,"religion-spirituality",{"id":126,"doc_module":4,"doc_module_name":46,"category_name":129,"show_sort_weight":126,"slug":130},"World Cup","world-cup",{"id":132,"doc_module":4,"doc_module_name":46,"category_name":133,"show_sort_weight":132,"slug":134},10,"Lifestyle","lifestyle",{"id":22,"doc_module":4,"doc_module_name":46,"category_name":136,"show_sort_weight":106,"slug":137},"General","general"]