Open cardosec

Case 1B15C2 · AI security · L4 Advanced

Securing a RAG Pipeline

Practise as: Deep dive
  1. 01 Context
  2. 02 Mechanism
  3. 03 Lessons
What a strong answer covers

Try it out loud first. Then check yourself:

  1. Enforce document ACLs at retrieval time using the requesting user's identity; the vector DB must filter by permission.
  2. Ingestion is an attack surface: poisoned or injection-laden docs become trusted context. Vet and label sources.
  3. Embeddings are not anonymized: inversion attacks can reconstruct text, so protect the vector store like the source data.
  4. Multi-tenant stores need hard tenant isolation (separate namespaces/indexes), not just metadata filters in prompts.
  5. Log retrieved chunk IDs per answer for auditability, and apply output filters for PII and secrets.

If the interviewer pushes back

  • A document's permissions change in SharePoint. How quickly does your RAG index reflect it, and what is the risk window?
  • Maps to which OWASP LLM Top 10 item, and what does that list miss for RAG?

Go deeper

cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.