cd /news/artificial-intelligence/stale-document-poisoning-when-outdat… · home › topics › artificial-intelligence › article
[ARTICLE · art-140798] src=machinebrief.com ↗ pub= topic=artificial-intelligence verified=true sentiment=↓ negative

Stale-Document Poisoning: When Outdated Retrieval Overrides Correct Model Answers

A new arXiv paper (2609.31342v1) identifies "stale-document poisoning," a retrieval-augmented generation failure in which outdated retrieved evidence overrides a model's correct answer. Testing 317 verified knowledge reversals across medicine, law, software, and platform policy on 12 models, the authors found outdated retrieval flipped 30% of Llama and 37% of Qwen answers without any instruction to trust the document, rising to 66% and 75% with explicit follow instructions, while poisoning across four open models and four domains ranged from 17% to 91% and matched up-to-date evidence was followed in 97-100% of trials. A fixed recency-aware hybrid re-ranker cut poisoning by 4.6-10.0 points when dates were accurate, leading the authors to conclude that reliable RAG requires selective trust in whether retrieved evidence still applies.

by read1 min views1 publishedSep 28, 2026

arXiv:2609.31342v1 Announce Type: new Abstract: Retrieval-augmented generation (RAG) is often used to address outdated knowledge by providing external evidence. But retrieval helps only when that evidence is still valid. We identify a temporal alignment failure, stale-document poisoning, in which outdated evidence makes a model wrong despite answering correctly without retrieval. We construct a benchmark of 317 verified knowledge reversals across medicine, law, software, and platform policy, grounded in dated official sources. Across 12 models, recent medical reversals are harder than long-established ones. More importantly, outdated retrieval flips 30% of Llama and 37% of Qwen answers even without instructions to trust the document; explicit follow instructions raise these rates to 66% and 75%. Across four open models and four domains, poisoning ranges from 17-91%, while matched up-to-date evidence is followed in 97-100% of trials. To isolate temporal applicability, we keep the historical evidence unchanged across 50 reversals and vary only the evaluation date. A clear pattern emerges: dates alone produce only modest adaptation, but when models are explicitly told when the old evidence stops applying, the larger models switch to the appropriate answer almost perfectly. Causal interventions confirm that this validity information directly shapes the final decision. The same internal components also support broader comparison tasks, suggesting that temporal applicability can recruit a general reasoning mechanism used for other comparisons. Finally, a fixed recency-aware hybrid re-ranker reduces poisoning by 4.6-10.0 points when dates are accurate, with gains that depend on reliable temporal metadata. Reliable RAG therefore requires selective trust: models must determine not only what retrieved evidence says, but whether it still applies.

── more in #artificial-intelligence 4 stories · sorted by recency
── more on @arxiv 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
→ Live at https://your-agent.zahid.host ✓
Get free account → Pricing
from €0/mo · no card required
LIVE [news/stale-document-poiso…] indexed:0 read:1min 2026-09-28 · —