Skip to content

Author

Rohan Mehra

2 papers indexed here

We haven’t gathered this author’s papers yet. Follow them and we’ll fetch their work.

Not the right person? Other researchers publish under this name.

#small language model Open access Sep 2026

A Multi-Layer Security Framework for Prompt Injection and Knowledge Poisoning Mitigation in Agentic Retrieval-Augmented Generation Systems

Retrieval-Augmented Generation (RAG) improves the factual usefulness of Large Language Models (LLMs) by grounding generation in external knowledge. When RAG is combined with autonomous agents, the system can plan multi-step tasks, retrieve information, and invoke external tools, but the additional autonomy also creates new attack surfaces. This paper proposes a Multi-Layer Security Framework (MLSF) for agentic RAG systems that combines input inspection, retrieved-context security, provenance verification, tool authorization, and output verification. The framework is designed around a practical Python technology stack consisting of LangChain, LangGraph, Mistral Small, embeddings, ChromaDB, FastAPI, and Docker. A controlled evaluation environment is defined with five attack categories: direct prompt injection, indirect prompt injection, knowledge poisoning, tool misuse, and context manipulation.

Rohan Mehra · 0 citations
#small language model Open access Sep 2026

A Multi-Layer Security Framework for Prompt Injection and Knowledge Poisoning Mitigation in Agentic Retrieval-Augmented Generation Systems

Retrieval-Augmented Generation (RAG) improves the factual usefulness of Large Language Models (LLMs) by grounding generation in external knowledge. When RAG is combined with autonomous agents, the system can plan multi-step tasks, retrieve information, and invoke external tools, but the additional autonomy also creates new attack surfaces. This paper proposes a Multi-Layer Security Framework (MLSF) for agentic RAG systems that combines input inspection, retrieved-context security, provenance verification, tool authorization, and output verification. The framework is designed around a practical Python technology stack consisting of LangChain, LangGraph, Mistral Small, embeddings, ChromaDB, FastAPI, and Docker. A controlled evaluation environment is defined with five attack categories: direct prompt injection, indirect prompt injection, knowledge poisoning, tool misuse, and context manipulation.

Rohan Mehra · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.