Analysis
RAG, end to end | AI Security Playbook
Publication date unknown · Discovered aisecurity.zone
Page published
Publication date unknown · First observed: 10 Oct 2026
Coverage timeline
Single-source analysis — one report is available.
Why it matters
RAG systems place untrusted retrieved text in the same context as trusted instructions, so defenders need a consolidated reference to the pipeline's attack surface and the controls that close poisoning, injection, and cross-tenant leakage.
The "RAG, end to end" page from the AI Security Playbook is a reference entry that explains the RAG pipeline (ingest, chunk, embed, store, retrieve, ground) and catalogs its attack surface, including knowledge-base poisoning, retrieval manipulation (PoisonedRAG), authority spoofing (DACSI), indirect injection at scale, cross-tenant leakage, embedding inversion, and membership inference. It then lists defenses such as role-aware entitlement-checked retrieval, spotlighting and delimiting retrieved text, per-chunk provenance, and securing the vector store as raw data.