RAG Poisoning Attack on Natural Questions (NQ) (test)
1Poisoned RAG Scoreibm/granite-3.3-8b-instruct
Evaluation Results
| Method | Links | ||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| ibm/granite-3.3-8b-instructEvaluation protocol=strict incorrect-answer matching2026.03 | 1 | 0.93 | 0.93 | 0 | 0 | 1 | 0 | — | — | — | — | — | |
| qwen/qwen2-7b-instructEvaluation protocol=strict incorrect-answer matching2026.03 | 0.96 | 0.88 | 0.76 | 0 | 0 | 1 | 0.04 | — | — | — | — | — | |
| qwen/qwen2.5-7b-instructEvaluation protocol=strict incorrect-answer matching2026.03 | 0.95 | 0.9 | 0.6 | 0 | 0 | 1 | 0.05 | — | — | — | — | — | |
| meta/llama-3.1-8b-instructEvaluation protocol=strict incorrect-answer matching2026.03 | 0.92 | 0.86 | 0.75 | 0 | 0 | 1 | 0.08 | — | — | — | — | — | |
| meta/llama-4-maverick-17b-128e-instructEvaluation protocol=strict incorrect-answer matching2026.03 | 0.92 | 0.92 | 0.91 | 0 | 0 | 1 | 0.08 | — | — | — | — | — | |
| meta/llama-3.3-70b-instructEvaluation protocol=strict incorrect-answer matching2026.03 | 0.91 | 0.86 | 0.86 | 0 | 0 | 1 | 0.09 | — | — | — | — | — | |
| openai/gpt-oss-120bEvaluation protocol=strict incorrect-answer matching2026.03 | 0.88 | 0.85 | 0.83 | 0 | 0 | 1 | 0.12 | — | — | — | — | — | |
| openai/gpt-oss-20bEvaluation protocol=strict incorrect-answer matching2026.03 | 0.8 | 0.54 | 0.79 | 0 | 0 | 0.96 | 0.16 | — | — | — | — | — | |
| GASLITERetriever=Contriever, Generator=Llama-2-7B-Chat, Judge=GPT-42026.05 | — | — | — | — | — | — | — | 76.8 | 58.7 | 44.1 | 38.6 | 31.2 | |
| Joint-GCGRetriever=Contriever, Generator=Llama-2-7B-Chat, Judge=GPT-42026.05 | — | — | — | — | — | — | — | 81.2 | 78.4 | 62.8 | 156.3 | 118.7 | |
| PoisonedRAGRetriever=Contriever, Generator=Llama-2-7B-Chat, Judge=GPT-42026.05 | — | — | — | — | — | — | — | 78.6 | 64.3 | 48.2 | 412.6 | 287.3 | |
| SilentRetrievalRetriever=Contriever, Generator=Llama-2-7B-Chat, Judge=GPT-42026.05 | — | — | — | — | — | — | — | 84.6 | 68.9 | 57.5 | 32.4 | 26.1 | |
| Zhong et al.Retriever=Contriever, Generator=Llama-2-7B-Chat, Judge=GPT-42026.05 | — | — | — | — | — | — | — | 72.3 | 51.2 | 38.4 | 847.2 | 612.4 |