arXiv:2501.14050cs.LGcs.AI2025-01中稿 · IEEE Symposium on …被引 30

揭露GraphRAG的新型安全漏洞,提出可同时攻击多查询的精准毒化方法。

GraphRAG under Fire

  • 利用知识图谱共享关系注入虚假信息,实现高效污染
  • 在多种GraphRAG变体上达到98%攻击成功率,用少于68%毒化文本
  • 适合关注AI安全、知识增强模型防御的研究者

GraphRAG通过多尺度知识图谱结构化外部知识,使语言模型能融合宏观上下文与细节信息。尽管其跨领域表现优异,安全风险仍待研究。本文揭示其安全悖论:传统RAG毒化攻击在GraphRAG中效果更弱,但图结构也带来新攻击面。提出GragPoison攻击,利用知识图谱中的共享关系,通过关系注入、关系增强和叙事生成三策略,生成可同时影响多个查询的恶意内容。在多个数据集与模型上的实证表明,GragPoison在有效性(最高98%成功率)和可扩展性(使用<68%毒化文本)上显著优于现有方法。同时探讨了防御措施及其局限,指明未来研究方向。

原文摘要 · Abstract (English)

GraphRAG advances retrieval-augmented generation (RAG) by structuring external knowledge as multi-scale knowledge graphs, enabling language models to integrate both broad context and granular details in their generation. While GraphRAG has demonstrated success across domains, its security implications remain largely unexplored. To bridge this gap, this work examines GraphRAG's vulnerability to poisoning attacks, uncovering an intriguing security paradox: existing RAG poisoning attacks are less effective under GraphRAG than conventional RAG, due to GraphRAG's graph-based indexing and retrieval; yet, the same features also create new attack surfaces. We present GragPoison, a novel attack that exploits shared relations in the underlying knowledge graph to craft poisoning text capable of compromising multiple queries simultaneously. GragPoison employs three key strategies: (i) relation injection to introduce false knowledge, (ii) relation enhancement to amplify poisoning influence, and (iii) narrative generation to embed malicious content within coherent text. Empirical evaluation across diverse datasets and models shows that GragPoison substantially outperforms existing attacks in terms of effectiveness (up to 98% success rate) and scalability (using less than 68% poisoning text) on multiple variations of GraphRAG. We also explore potential defensive measures and their limitations, identifying promising directions for future research.

知识图谱安全攻防RAG

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。