Retrieval-augmented generation

AgentPoison

AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases

Superseded baseline#113 of 1,179 most-superseded · first seen Jul 17, 2024

Superseded — cited as a baseline and beaten by newer methods

1 papers critique it · 1 beat it on benchmarks

What papers say

Verbatim critique sentences, each from a paper that cites AgentPoison as a baseline.

these methods inevitably introduce abnormal inference behaviors and new security risks to the deployed LLMs as these distinctive behaviors are generating incorrect results on particular verification prompts/questions
Towards Copyright Protection for Knowledge Bases of Retrieval-augmented Language Models via Reasoning

Beaten on benchmarks

Head-to-head results where a newer method reports beating AgentPoison. Values are copied from the source paper's tables — verify against the cited paper.

What to use instead

Recent methods in the same sub-problem, not yet superseded in the knowledge base — arXiv benchmark leaders, not vetted production recommendations.