MaSS: Model-agnostic, Semantic and Stealthy Data Poisoning Attack on Knowledge Graph Embedding
Xiaoyu You, Beina Sheng, Daizong Ding, Mi Zhang, Xudong Pan, Min Yang, Fuli Feng
Abstract
Open-source knowledge graphs are attracting increasing attention. Nevertheless, the openness also raises the concern of data poisoning attacks, that is, the attacker could submit malicious facts to bias the prediction of knowledge graph embedding (KGE) models. Existing studies on such attacks adopt a clear-box setting and neglect the semantic information of the generated facts, making them fail to attack in real-world scenarios. In this work, we consider a more rigorous setting and propose a model-agnostic, semantic, and stealthy data poisoning attack on KGE models from a practical perspective. The main design of our work is to inject indicative paths to make the infected model predict certain malicious facts. With the aid of the proposed opaque-box path injection theory, we theoretically reveal that the attack success rate under the opaque-box setting is determined by the plausibility of triplets on the indicative path. Based on this, we develop a novel and efficient algorithm to search paths that maximize the attack goal, satisfy certain semantic constraints, and preserve certain stealthiness, i.e., the normal functionality of the target KGE will not be influenced although it predicts wrong facts given certain queries. Through extensive evaluation of benchmark datasets and 6 typical knowledge graph embedding models as the victims, we validate the effectiveness in terms of attack success rate (ASR) under opaque-box setting and stealthiness. For example, on FB15k-237, our attack achieves a ASR on DeepPath, with an average ASR over when attacking various KGE models under the opaque-box setting.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Cited by top-tier papers4
- Complex Query Answering on Eventuality Knowledge Graph with Implicit Logical ConstraintsJiaxin Bai, Xin Liu, Weiqi Wang, Chen Luo et al.NeurIPS 2023 · 46 citations
- Enhancing Transformers for Generalizable First-Order Logical EntailmentTianshi Zheng, Jiazheng Wang, Zihao Wang, Jiaxin Bai et al.ACL 2025 · 7 citations
- Poisoning Attack on Federated Knowledge Graph EmbeddingEnyuan Zhou, Song Guo, Zhixiu Ma, Zicong Hong et al.WWW 2024 · 6 citations
- Untargeted Adversarial Attack on Knowledge Graph EmbeddingsTianzhe Zhao, Jiaoyan Chen, Yanchi Ru, Qika Lin et al.SIGIR 2024 · 5 citations
Related papers
- Poisoning Knowledge Graph Embeddings via Relation Inference PatternsPeru Bhardwaj, John D. Kelleher, Luca Costabello, Declan O'SullivanACL 2021
- Adversarial Attacks on Knowledge Graph Embeddings via Instance Attribution MethodsPeru Bhardwaj, John D. Kelleher, Luca Costabello, Declan O'SullivanEMNLP 2021 · 17 citations
- Unveiling and Mitigating Untargeted Poisoning Attacks on Federated Knowledge Graph EmbeddingWenzheng Jiang, Ke Liang, Wenke Huang, Xiongtao Zhang et al.WWW 2026
- A Restricted Black-Box Adversarial Framework Towards Attacking Graph Embedding ModelsHeng Chang, Yu Rong, Tingyang Xu, Wenbing Huang et al.AAAI 2020 · 171 citations
- Meta-Knowledge Transfer for Inductive Knowledge Graph EmbeddingMingyang Chen, Wen Zhang, Yushan Zhu, Hongting Zhou et al.SIGIR 2022 · 69 citations
