CiteShade: one poisoned source pushes multi-hop RAG wrong-answer rate from 1% to 68% while citing a trustworthy source that never supported the claim
A September 14 arXiv paper turns the citation trail, normally the audit mechanism, into the attack surface. An attacker controlling a single source in multi-source retrieval gets the system to produce an attacker-chosen wrong answer, attribute it to a trusted source that does not support it, and leave the correct evidence retrieved but unused. Wrong-answer rate rose from 0.01 to 0.68 on multi-source multi-hop QA, with a citation laundering rate of 0.84 under explicit instruction and 0.64 with no instruction on the most citation-prone model; perplexity filtering and citation-support checking each proved insufficient alone, and the authors propose a counterfactual check of which source actually drove generation.
Source
↳ Follow the thread