ai-research
The Single-Reranker Substitution Attack: How One Cross-Encoder Becomes the Attack Surface of Your RAG Pipeline
Hover / tap to read moreThe Single-Reranker Substitution Attack: How One Cross-Encoder Becomes the Attack Surface of Your RAG Pipeline
A RAG pipeline's reranker can substitute one valid document for another — wrong-but-related — while passing every standard rank-based eval. Here is the substitution mechanism, the SNF probe that detects it, and the architectural change that dilutes the reranker's authority over final order.