{
  "story_id": "dd4753619552ae177ed07cfdd8c35e41",
  "desk": "drm3",
  "revision": 1,
  "published_at": "2026-09-02T04:00:00.000Z",
  "content_hash": "755728bc89a23875eddb14d6f171735e2cea7e0a3a9068280217253899144607",
  "hash_basis": "sha256 over `headline\\ndek\\nprose`, plus `\\n` + the canonical citations JSON when any source is placed, plus `\\n#blog` for blogs",
  "basis": {
    "headline": "Researchers Propose VerTox Framework to Poison Neural Ranking Models",
    "dek": "New research introduces VerTox, a framework that uses reinforcement learning to generate adversarial documents that corrupt neural ranking systems.",
    "prose": "The authors propose VerTox, the first framework to formulate corpus poisoning as a verifiable reward-guided reinforcement learning problem for neural ranking models. [^1]\n\nBy explicitly encouraging factual corruption, the adversarial documents generated by VerTox significantly degrade the performance of a downstream retrieval-augmented generation (RAG) application. [^2]\n\nExperiments demonstrate that the VerTox method achieves near-perfect attack success rates, producing adversarial documents that frequently rank higher than target documents across major neural ranking architectures. [^3]\n\nThe VerTox framework explicitly couples ranking distortion with factual corruption through specialized reward shaping to fine-tune compact large language models into adversarial generators. [^4]\n\nThe article states that the difficult part of Retrieval-Augmented Generation (RAG) does not end once the retriever returns the correct text chunks. [^5]\n\nThe author asserts that retrieved chunks must still be merged with the user's query to be effectively used. [^6]\n\nThe text implies that without merging retrieved context with the query, the RAG process is incomplete. [^7]",
    "cited": "[{\"statement\":\"The authors propose VerTox, the first framework to formulate corpus poisoning as a verifiable reward-guided reinforcement learning problem for neural ranking models.\",\"source\":\"arXiv.org\",\"instrument\":\"News\",\"claim_key\":null,\"published_at\":\"2026-09-02T04:00:00.000Z\",\"publisher_count\":1,\"sources\":[\"arXiv.org\"]},{\"statement\":\"By explicitly encouraging factual corruption, the adversarial documents generated by VerTox significantly degrade the performance of a downstream retrieval-augmented generation (RAG) application.\",\"source\":\"arXiv.org\",\"instrument\":\"News\",\"claim_key\":null,\"published_at\":\"2026-09-02T04:00:00.000Z\",\"publisher_count\":1,\"sources\":[\"arXiv.org\"]},{\"statement\":\"Experiments demonstrate that the VerTox method achieves near-perfect attack success rates, producing adversarial documents that frequently rank higher than target documents across major neural ranking architectures.\",\"source\":\"arXiv.org\",\"instrument\":\"News\",\"claim_key\":null,\"published_at\":\"2026-09-02T04:00:00.000Z\",\"publisher_count\":1,\"sources\":[\"arXiv.org\"]},{\"statement\":\"The VerTox framework explicitly couples ranking distortion with factual corruption through specialized reward shaping to fine-tune compact large language models into adversarial generators.\",\"source\":\"arXiv.org\",\"instrument\":\"News\",\"claim_key\":null,\"published_at\":\"2026-09-02T04:00:00.000Z\",\"publisher_count\":1,\"sources\":[\"arXiv.org\"]},{\"statement\":\"The article states that the difficult part of Retrieval-Augmented Generation (RAG) does not end once the retriever returns the correct text chunks.\",\"source\":\"medium.com\",\"instrument\":\"News\",\"claim_key\":null,\"published_at\":\"2026-09-01T14:54:47.000Z\",\"publisher_count\":1,\"sources\":[\"medium.com\"]},{\"statement\":\"The author asserts that retrieved chunks must still be merged with the user's query to be effectively used.\",\"source\":\"medium.com\",\"instrument\":\"News\",\"claim_key\":null,\"published_at\":\"2026-09-01T14:54:47.000Z\",\"publisher_count\":1,\"sources\":[\"medium.com\"]},{\"statement\":\"The text implies that without merging retrieved context with the query, the RAG process is incomplete.\",\"source\":\"medium.com\",\"instrument\":\"News\",\"claim_key\":null,\"published_at\":\"2026-09-01T14:54:47.000Z\",\"publisher_count\":1,\"sources\":[\"medium.com\"]}]",
    "kind": "news"
  },
  "receipt_verify": "Ed25519 over the dot-joined string `slice_hash.cursor_from.cursor_to.view.view_version.row_count`; public_key and sig are base64url of the raw 32-byte key / 64-byte signature",
  "receipt": null,
  "receipt_note": "this revision predates receipt-keeping (before v0.37.0); the filed row lives in the record",
  "generation_chain": {
    "wire": {
      "stream": "fountain_news",
      "story_id": "76c41077b8df77e333354c186a083275",
      "thread_id": "d1630af224d3307e1b4826c8aa00c786",
      "thread_label": "Retrieval-Augmented Generation",
      "novelty": "UPDATE",
      "content_hash": "b8244327a96a9d54b3eb2adf2400adea769deee224d8ecb76b26dbe7633e5757",
      "last_published_at": "2026-09-02T04:00:00.000Z",
      "read_receipt": {
        "slice_hash": "3905664cf10c2126ea131af76eb59a4e670141af2a4606d101f9336a8aaf6e3e",
        "cursor_from": "eyJ0cyI6IjIwMjYtMDktMDJUMDM6NDM6MDAuMDAwMDAwWiIsImlkIjoiZjIzZjc5YTk3YjM4MGMyNDgzZTRlNzYxMjNlZjg2M2QiLCJ2IjoiMSJ9",
        "cursor_to": "eyJ0cyI6IjIwMjYtMDktMDJUMDQ6MDQ6MjYuMDAwMDAwWiIsImlkIjoiN2M3MjY3YjA5MzczMjU3ZjI0ZDZiY2NmZWY3ZDVjNGUiLCJ2IjoiMSJ9",
        "view": "v_fountain_news",
        "view_version": "1",
        "row_count": 100,
        "window_days": 3,
        "bytes_scanned": 12017721,
        "credits": 8,
        "price_per_100_rows": 8,
        "sig": "juwMycx6aGSQfawfzLUaISZZUKKkbvDiOPDpZxKn6fmy0KIBoISR1qDjkJuogjQ0TUgCk4tYeoc9JF0bPKfOCw",
        "public_key": "bMUigy8O0jOnBxQ4Sc-5lwhIZ8LQVAhxMbR7qESVuUE",
        "signer_path": "lakehouse/data-extract/v1",
        "alg": "Ed25519",
        "signed": true
      }
    },
    "written_at": "2026-09-02T22:35:59.415Z"
  },
  "cited_facts": [
    {
      "statement": "The authors propose VerTox, the first framework to formulate corpus poisoning as a verifiable reward-guided reinforcement learning problem for neural ranking models.",
      "source": "arXiv.org",
      "instrument": "News",
      "claim_key": null,
      "published_at": "2026-09-02T04:00:00.000Z",
      "publisher_count": 1,
      "sources": [
        "arXiv.org"
      ]
    },
    {
      "statement": "By explicitly encouraging factual corruption, the adversarial documents generated by VerTox significantly degrade the performance of a downstream retrieval-augmented generation (RAG) application.",
      "source": "arXiv.org",
      "instrument": "News",
      "claim_key": null,
      "published_at": "2026-09-02T04:00:00.000Z",
      "publisher_count": 1,
      "sources": [
        "arXiv.org"
      ]
    },
    {
      "statement": "Experiments demonstrate that the VerTox method achieves near-perfect attack success rates, producing adversarial documents that frequently rank higher than target documents across major neural ranking architectures.",
      "source": "arXiv.org",
      "instrument": "News",
      "claim_key": null,
      "published_at": "2026-09-02T04:00:00.000Z",
      "publisher_count": 1,
      "sources": [
        "arXiv.org"
      ]
    },
    {
      "statement": "The VerTox framework explicitly couples ranking distortion with factual corruption through specialized reward shaping to fine-tune compact large language models into adversarial generators.",
      "source": "arXiv.org",
      "instrument": "News",
      "claim_key": null,
      "published_at": "2026-09-02T04:00:00.000Z",
      "publisher_count": 1,
      "sources": [
        "arXiv.org"
      ]
    },
    {
      "statement": "The article states that the difficult part of Retrieval-Augmented Generation (RAG) does not end once the retriever returns the correct text chunks.",
      "source": "medium.com",
      "instrument": "News",
      "claim_key": null,
      "published_at": "2026-09-01T14:54:47.000Z",
      "publisher_count": 1,
      "sources": [
        "medium.com"
      ]
    },
    {
      "statement": "The author asserts that retrieved chunks must still be merged with the user's query to be effectively used.",
      "source": "medium.com",
      "instrument": "News",
      "claim_key": null,
      "published_at": "2026-09-01T14:54:47.000Z",
      "publisher_count": 1,
      "sources": [
        "medium.com"
      ]
    },
    {
      "statement": "The text implies that without merging retrieved context with the query, the RAG process is incomplete.",
      "source": "medium.com",
      "instrument": "News",
      "claim_key": null,
      "published_at": "2026-09-01T14:54:47.000Z",
      "publisher_count": 1,
      "sources": [
        "medium.com"
      ]
    }
  ],
  "note": "A signature proves who filed this and that it has not changed since. It never makes a claim true."
}