DGV-TC-031L2: Component & ProvenanceGER-427: Corpus Poisoning UndetectedVersion: 1.0.0
RAG Corpus Digest Verification
Verifies that the RAG corpus loaded at query time matches the SHA-256 digest registered in the Agent Manifest at deployment. A corpus that has been modified, poisoned, or swapped since signing causes immediate gate closure before any retrieval-augmented generation is permitted.
Operational Purpose & Scope
Real SHA-256 of the corpus is computed by only-gate and compared to the deliberately wrong registered digest. Gate closes on mismatch.
Verification Context
- Target Scope:
Agent Manifest corpus binding; only-engine gateway RAG query path - Audit Strategy:
exact-match - Verification Metrics:
gate_statusrejection_reasonregistered_digest_presentobserved_digest_presentcorpus_digest_verified - Framework Origin:DGV v0.5.0 Expansion
- Mandatory:Yes — must pass for certification
Governance Risk & Penalty
Corrupted RAG corpus enables data poisoning attacks, producing manipulated retrieval-augmented outputs.
Expected Outcome
- gate_status:
"CLOSE" - rejection_reason:
"rag_corpus_digest_mismatch" - registered_digest_present:
true - observed_digest_present:
true
Explore this card in 3D
Open DGV-TC-031 in the interactive scenario replay. This illustrates the test flow; it does not run the verifier or generate a cryptographic receipt.
Open DGV Live →