MITRE ATLAS 2026 Top AI Detection: False RAG Entry Injection via Unauthorized Vector Store Write (AML.T0071)

Detects unauthorized or anomalous write operations (upsert/insert) to a vector database, which could indicate a Retrieval-Augmented Generation (RAG) injection attack. The rule monitors for writes from non-sanctioned identities, operations outside of established maintenance or ingestion windows, or entries that lack necessary provenance metadata such as source document IDs or content hashes.