RADAR: Defending RAG Dynamically against Retrieval Corruption

Ziyuan Chen, Yueming Lyu, Yi Liu, Weixiang Han, Jing Dong, Caifeng Shan, Tieniu Tan
Proceedings of the 43rd International Conference on Machine Learning, PMLR 306:15999-16021, 2026.

Abstract

While RAG systems are increasingly deployed in dynamic web search, temporal volatility amplifies their vulnerability to adversarial attacks. Existing static-oriented defenses struggle to handle evolving threats and incur prohibitive storage costs in dynamic settings. We propose RADAR, a framework that models reliable context selection as a graph-based energy minimization problem, solved exactly via Max-Flow Min-Cut. By incorporating a Bayesian memory node, RADAR recursively updates a belief state instead of archiving raw historical documents, effectively balancing stability against attacks with adaptability to genuine knowledge shifts. Experiments on a novel dynamic dataset show that RADAR achieves superior robustness and response quality with minimal storage overhead compared to the baselines.

Cite this Paper


BibTeX
@InProceedings{pmlr-v306-chen26cw, title = {{RADAR}: Defending {RAG} Dynamically against Retrieval Corruption}, author = {Chen, Ziyuan and Lyu, Yueming and Liu, Yi and Han, Weixiang and Dong, Jing and Shan, Caifeng and Tan, Tieniu}, booktitle = {Proceedings of the 43rd International Conference on Machine Learning}, pages = {15999--16021}, year = {2026}, editor = {Zhang, Tong and Dudik, Miroslav and Jaggi, Martin and Agarwal, Alekh and Li, Sharon and Schuurmans, Dale and Zhu, Jerry and Berkenkamp, Felix and Dong, Hanze and Bietti, Alberto}, volume = {306}, series = {Proceedings of Machine Learning Research}, month = {06--11 Jul}, publisher = {PMLR}, pdf = {https://raw.githubusercontent.com/mlresearch/v306/main/assets/chen26cw/chen26cw.pdf}, url = {https://proceedings.mlr.press/v306/chen26cw.html}, abstract = {While RAG systems are increasingly deployed in dynamic web search, temporal volatility amplifies their vulnerability to adversarial attacks. Existing static-oriented defenses struggle to handle evolving threats and incur prohibitive storage costs in dynamic settings. We propose RADAR, a framework that models reliable context selection as a graph-based energy minimization problem, solved exactly via Max-Flow Min-Cut. By incorporating a Bayesian memory node, RADAR recursively updates a belief state instead of archiving raw historical documents, effectively balancing stability against attacks with adaptability to genuine knowledge shifts. Experiments on a novel dynamic dataset show that RADAR achieves superior robustness and response quality with minimal storage overhead compared to the baselines.} }
Endnote
%0 Conference Paper %T RADAR: Defending RAG Dynamically against Retrieval Corruption %A Ziyuan Chen %A Yueming Lyu %A Yi Liu %A Weixiang Han %A Jing Dong %A Caifeng Shan %A Tieniu Tan %B Proceedings of the 43rd International Conference on Machine Learning %C Proceedings of Machine Learning Research %D 2026 %E Tong Zhang %E Miroslav Dudik %E Martin Jaggi %E Alekh Agarwal %E Sharon Li %E Dale Schuurmans %E Jerry Zhu %E Felix Berkenkamp %E Hanze Dong %E Alberto Bietti %F pmlr-v306-chen26cw %I PMLR %P 15999--16021 %U https://proceedings.mlr.press/v306/chen26cw.html %V 306 %X While RAG systems are increasingly deployed in dynamic web search, temporal volatility amplifies their vulnerability to adversarial attacks. Existing static-oriented defenses struggle to handle evolving threats and incur prohibitive storage costs in dynamic settings. We propose RADAR, a framework that models reliable context selection as a graph-based energy minimization problem, solved exactly via Max-Flow Min-Cut. By incorporating a Bayesian memory node, RADAR recursively updates a belief state instead of archiving raw historical documents, effectively balancing stability against attacks with adaptability to genuine knowledge shifts. Experiments on a novel dynamic dataset show that RADAR achieves superior robustness and response quality with minimal storage overhead compared to the baselines.
APA
Chen, Z., Lyu, Y., Liu, Y., Han, W., Dong, J., Shan, C. & Tan, T.. (2026). RADAR: Defending RAG Dynamically against Retrieval Corruption. Proceedings of the 43rd International Conference on Machine Learning, in Proceedings of Machine Learning Research 306:15999-16021 Available from https://proceedings.mlr.press/v306/chen26cw.html.

Related Material