RAG-NAROK: What Poorly-Built RAGs Can Do to Data Security

By Akash Mukherjee , Saurabh Shintre on 29 Apr 2025 @ Rsac
🔗 Link
secure-development devsecops data-protection vulnerability-management security-architecture
Focus Areas: Privacy , Application Security , Data Security , DevSecOps , Security Architecture , Vulnerability Management

Abstract

Retrieval Augmented Generation (RAG) can cause serious data security problems as they require moving data into new locations like VectorDBs that do not support access controls. The increasing popularity of low-code, no-code tools exacerbates the situation. This session will demonstrate these issues in practice and share experiences in building secure RAGs as well as do’s and don’t of AI security.