Tag
This paper proposes that only AI agents capable of System 2 thinking should access untrusted documents in RAG systems to enhance security, introducing new metrics to evaluate robustness and showing reasoning models are more resistant to knowledge poisoning.