acceptodds
Under review as a conference paper at ICLR 2027

CyclicRA: Inducing Retrieval Loops for Resource Exhaustion in Agentic RAG

Abstract

Agentic RAG enables large language model (LLM) agents to iteratively coordinate reasoning, retrieval, and action based on evolving execution contexts, where retrieved evidence continuously affects subsequent execution. This iterative dependence exposes a new attack surface: poisoned documents can steer the agent toward unnecessary reasoning and retrieval, substantially increasing resource consumption. However, existing Denial-of-Efficiency attacks largely focus on direct manipulation of agent inputs, leaving the resource-exhaustion risks arising from the retrieval process itself largely unexplored. To systematically exploit this attack surface, we propose CyclicRA, a corpus-poisoning attack that steers the agent's retrieval trajectory by inducing self-sustaining retrieval loops. CyclicRA generates poisoned documents that provide seemingly useful evidence while introducing unresolved information gaps, encouraging the agent to issue additional retrieval queries. It further guides the agent through a sequence of intermediate queries, aiming to form a retrieval loop in which subsequent queries return to a previously issued query. This loop repeatedly extends the agent's reasoning and retrieval process beyond what is required for task completion. Experiments across five models on both single-hop and multi-hop question-answering benchmarks show that CyclicRA induces an average of 11.63 additional retrieval steps over clean execution and consumes 1.82x as many tokens as SOTA baseline attacks on average, while remaining effective under different defense measures.

Then back it, or bet against it.

Related papers

Open the market on this paper to see 7 more related papers.