CoRe-DoS: Inference-time denial-of-service attack against retrieval-augmented generation
Haocheng Sun, Deyu Yuan, Mingfeng Li, Yuyang Deng · Computer Networks · 2026
Retrieval-Augmented Generation (RAG) technology significantly mitigates the hallucination problem in large language models by integrating external knowledge bases, but its distributed architecture also introduces new security risks. Existing research on attacks against RAG systems primarily focuses on knowledge poisoning, which directly contaminates external knowledge bases and requires attackers to have permission to modify the knowledge base. However, these methods overlook the interceptability of retrieved context during the inference phase of RAG systems, leaving the inference-time attack vector insufficiently explored. To address this issue, this paper proposes CoRe-DoS, an inference-time denial-of-service attack framework for retrieval-augmented generation. Rather than poisoning the knowledge base, this framework intercepts and manipulates retrieved context during inference, exploiting the instruction-following characteristics and position bias of large language models to induce the model to refuse answering legitimate queries. Meanwhile, it introduces a black-box capacity inference mechanism and an instruction-preserving compression mechanism to ensure the integrity of attack payloads under unknown context window constraints. Experimental results demonstrate that CoRe-DoS achieves attack success rates ranging from 84.6% to 100% across two benchmark datasets and multiple mainstream models, significantly outperforming baseline methods. It also maintains relatively high effectiveness under mainstream defense mechanisms, including perplexity filtering, document rewriting, knowledge expansion, and a RAGuard-style composed defense.