RootCert: Certified RAG Under Bounded Authenticated-Principal Poisoning
Abstract
A single compromised writer can corrupt retrieval-augmented generation(RAG) by introducing numerous records into external knowledge sources, making record-count budgets sensitive to fragmentation and replication. RootCert addresses this issue by counting authenticated writer IDs, called principals, instead of records. It certifies a fixed query's reference answer against any finite append through at most principals after an immutable memory checkpoint. Our central contribution is a principal-to-selection reduction. We score records separately, convexly pool them into one bounded vector per principal, and select the top- ranked groups without merging them. If the identities, scores, and relative order of the unaffected candidates remain fixed, this deterministic procedure requires at most matched score replacements. The standard bounded-replacement argument then ensures answer invariance when the reference answer's margin over its strongest competitor exceeds . On StrategyQA, across two readers and three retrievers with frozen candidate exposure, the principal-based-certification maintains accuracy from to appended records, whereas the record-based scalar certification fails after six records. A RootCert-aware adaptive attacker alters of uncertified answers at without affecting any certified reference. Principal-splitting tests, additional readers, and HotpotQA are used to examine separately declared threat sets. Under these conditions, RootCert safeguards certified answers against any finite record volume within a principal budget.
Then back it, or bet against it.
Related papers
Open the market on this paper to see 7 more related papers.