Scenario-Based AI Engineering Questions

Course Content

Scenario-Based AI Engineering Questions

26 sections · 146 lessons

A malicious user manipulates retrieval rankings by repeatedly uploading keyword-stuffed documents. How do you defend vector search systems against retrieval poisoning attacks?


Top 8 for "how do I get a refund", by sourceseller-4412seller-4412seller-4412seller-4412officialseller-4412help-wikiseller-441201234567stuffedrightanswer, rank 5A cap of two results per uploader and a trust prior move the official page to rank 1.
Similarity alone lets one uploader own the result list; provenance is what lets ranking tell them apart.

What you need to know

What stuffing looks like

A stuffed document repeats target phrases ("refund policy refund process how to get refund...") so its embedding and its keyword score sit close to many queries. It has a signature:

Python
from collections import Counterdef stuffing_features(text: str) -> dict:    words = text.lower().split()    counts = Counter(words)    top_share = sum(c for _, c in counts.most_common(5)) / max(len(words), 1)    trigrams = [" ".join(words[i:i + 3]) for i in range(len(words) - 2)]    repeat_trigrams = 1 - len(set(trigrams)) / max(len(trigrams), 1)    return {"unique_ratio": len(counts) / max(len(words), 1),            "top5_share": top_share,            "repeated_trigrams": repeat_trigrams}

Normal prose has a high share of unique words and few repeated three-word phrases. Compare each upload's features with your corpus and quarantine strong outliers for review before embedding. A second signal is hubness: an embedding that is unusually close to many unrelated query clusters.

Rank with trust, not similarity alone

DefenceWhy it helps
Provenance on every chunkUploader, source, time and trust tier make ranking and cleanup possible
Upload quotas per userOne account cannot add 10,000 documents to a shared corpus unreviewed
Source-trust priorOfficial docs above wiki above user uploads, blended into the score
Cross-encoder rerankerReads query and passage together, so simple repetition helps much less
Diversity (MMR) and per-source capsOne uploader cannot fill the top-K

A stuffed document can win on cosine similarity; it should not win the blended score.

Better attackers write fluent text aimed at specific questions rather than repeating keywords. Research such as PoisonedRAG has shown that a few crafted passages can steer answers, which is why provenance and trust tiers matter more than any single content filter.

Detect and clean up

  1. Score at ingestion — stuffing features and hubness; quarantine outliers.
  2. Rank with trust — blended score, rerank, per-source caps.
  3. Watch fan-out — alert when a document suddenly appears in the top-K for a wide range of unrelated queries, and auto-quarantine above a threshold.
  4. Purge by provenance — remove everything a bad uploader added in one operation, and re-run affected queries to check answers.

A real-life example

Scenario, numbers made up. A marketplace's help assistant searches official help pages plus seller-uploaded guides. One seller uploads 3,000 short documents stuffed with "refund", "cancel order" and "customer care number", each containing a fake phone number. Within a day, 7 of the top 8 results for refund questions are from that seller, and the assistant starts quoting the scam number.

Fan-out monitoring flags the documents because they rank for 400 unrelated query clusters. The team purges everything from that uploader using provenance, adds a trust prior that ranks official pages first, caps results at 2 per uploader, and rejects uploads with a top-5-word share above the corpus 99th percentile. New seller uploads now go through a review queue once a seller passes 50 documents a day.

Follow-up questions to expect

  • "Is a cross-encoder enough?" — No. It makes simple stuffing much less effective, but crafted, fluent passages can still rank; you need trust tiers and provenance too.
  • "How would you tell the user about lower-trust sources?" — Show the source type on each citation, and prefer official sources for policy answers such as refunds or phone numbers.
  • "What about poisoning through a trusted source?" — Treat any editable source as lower trust than reviewed content, and version official pages so a bad edit can be rolled back.