Case 1B15C2 · AI security · L4 Advanced
Securing a RAG Pipeline
Practise as: Deep dive
- 01 Context
- 02 Mechanism
- 03 Lessons
What a strong answer covers
Try it out loud first. Then check yourself:
- Enforce document ACLs at retrieval time using the requesting user's identity; the vector DB must filter by permission.
- Ingestion is an attack surface: poisoned or injection-laden docs become trusted context. Vet and label sources.
- Embeddings are not anonymized: inversion attacks can reconstruct text, so protect the vector store like the source data.
- Multi-tenant stores need hard tenant isolation (separate namespaces/indexes), not just metadata filters in prompts.
- Log retrieved chunk IDs per answer for auditability, and apply output filters for PII and secrets.
If the interviewer pushes back
- A document's permissions change in SharePoint. How quickly does your RAG index reflect it, and what is the risk window?
- Maps to which OWASP LLM Top 10 item, and what does that list miss for RAG?
Go deeper
cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.