Definition
Plain language
An earlier attack that slipped fake text into an AI's search results.
As stated in the literature
A prior text-centric multimodal RAG poisoning method; because its payload is textual, it is caught reliably by jailbreak-detection and fact-checking filters applied to retrieved content.
Why it matters: Because its payload is written words, ordinary content filters can spot it — which sets the bar that purely visual attacks are designed to slip under.
For example, an attacker plants a document whose text tells the model to ignore other sources and give a specific wrong answer.
Heard on the show
“A prior text-injection attack called PoisonedEye, same pipeline, was blocked one hundred percent of the time in their sample.”Episode 247 — One Edited Photo, an Honest Caption, and a RAG System That Believes It