retrieval-moves-the-trust-boundary-rather-than-removing-it
mechanismreplicated

Grounding answers in retrieved documents reduces unsupported generation but transfers the trust problem to the retrieval channel: whatever lands in context is treated as reliable, which shows up both as following instructions planted in retrieved content and as deferring to whichever account is better represented when sources disagree.

Capability: Stating false facts confidently · Knowledge, Retrieval-augmented QA

Sources

Status: activeLast checked: 2026-09-04Evidence activityHow much the field cites the sources under this claimvery heavily cited in the last 12 months1000+ in 12mo · 1870 total — Not what you've signed up for: Compromising Real-World LLM-Integrated Applications with Indirect Prompt Injection148 in 12mo · 382 total — Adaptive Chameleon or Stubborn Sloth: Revealing the Behavior of Large Language Models in Knowledge Conflicts
Contest this claim

Disagreeing is the most useful thing you can do here. Both sides of every contested claim in this catalog were assembled by the same person, which is its weakest point.

Related claims

Notes

Not an argument against retrieval — the reduction in unsupported generation is real and filed separately. This is the scope condition: retrieval is only as trustworthy as the channel feeding it, so the defenses belong at the boundary (see the prompt-injection capability), not in the generation step. Replicated in the sense of two independent papers reaching the same mechanism from different failure modes.