KezoSec/rag-poisoning-lab
A self-contained AI security lab demonstrating document poisoning, indirect prompt injection, and data exfiltration in RAG systems. Explores the "helpfulness paradox" across local and frontier LLMs.
SUMMARY AI summary by gpt-5-mini
A self-contained Docker lab that demonstrates four classes of attacks against Retrieval-Augmented Generation (RAG) systems and defenses, validated on a local model (Llama 3.2 3B) and a frontier model (Claude Haiku 4.5). Intended for security researchers, red teams, and engineers building/defending RAG pipelines. Key features: - Reproducible attack scripts that inject payloads into a Chroma vector DB (document poisoning, indirect prompt injection, data exfiltration, PDF invisible-text smuggling). - Local offline Llama via Ollama and optional Anthropic Claude integration; sentence-transformers embeddings; Docker Compose orchestration. - Working defense: regex-based output filter and JSON evidence for each outcome. - Headline finding: stronger reasoning/helpfulness in frontier models can increase susceptibility to content-poisoning; model safety is shape-based, so retrieval-layer controls are required.
DETECTED Detected AI stack
AI-related keywords found in this repo's description, topics, or README summary — grouped by category. Each badge links to the corresponding ranking detail page.
GitHub Topics
Language breakdown (by bytes)
Why this is classified AI-related
The AI relevance score checks four places for AI keywords and adds the weight of each one that matches. Full methodology
Total AI relevance score: 100 / 100
Position among AI repos in the same language
We track 12,475 Python repos, of which 9,636 score 40 or above on AI relevance. 517 have more stars than this one (top 4.2%), and 0 score higher (top 0.0%).
Owner
Dates
| Created on GitHub | 2026-05-09 |
| Last push | 2026-05-09 |
| First seen here | 2026-05-09 |
| Last fetched | 2026-08-17 16:13 |
Similar repos (same language)
A trilingual (繁中 / English / 简中) learning roadmap for agentic AI: from LLM basics to multi-agent systems, with 240+ curated resources and hands-on examples. 中文 AI agent 學習地圖。
Sophomoresty/gemini-web2apiConvert Google Gemini web into OpenAI-compatible API. Zero auth, cross-platform, single file.
AminBlg/SimpleEnglishAgent skill: make LLMs write docs in ASD-STE100 Simplified Technical English — no AI slop
ray-r-ren/agent-apprenticeshipThe living ecosystem where AI agents complete tasks through workflow loops, improve through iterative execution, are evaluated by mentor agents or humans in the loop, and turn completed work into reusable work experience and data to improve future agents.
Intuition-Lab/personal-modelBuild your HUMAN.md.
Alisa0808/vox-directorTurn one topic into a finished Vox-style paper-collage explainer/ad video — automated end to end on Atlas Cloud + ffmpeg. An agent skill.
beizhu-1209/AIHelms企业级 AI 资源纳管平台,提供统一 AI网关、Token调度能力,纳管 OpenAI、Azure、Claude、DeepSeek 等主流模型,并支持 MCP 工具与 Skill 的集中注册分发。具备内外双轨定价、成本归因、统一身份认证、安全审计与效能报表,帮助企业精准控制成本、量化 ROI,高效治理 AI 资产。
lonr-6/cc-desktop-switchLightweight desktop tool for configuring DeepSeek, Kimi, Zhipu GLM and Bailian providers in Claude Desktop.