Adversarial Attacks on Knowledge Graph Embeddings via Instance Attribution Methods
Peru Bhardwaj, John D. Kelleher, Luca Costabello, Declan O'Sullivan
Abstract
Despite the widespread use of Knowledge Graph Embeddings (KGE), little is known about the security vulnerabilities that might disrupt their intended behaviour. We study data poisoning attacks against KGE models for link prediction. These attacks craft adversarial additions or deletions at training time to cause model failure at test time. To select adversarial deletions, we propose to use the model-agnostic instance attribution methods from Interpretable Machine Learning, which identify the training instances that are most influential to a neural model's predictions on test instances. We use these influential triples as adversarial deletions. We further propose a heuristic method to replace one of the two entities in each influential triple to generate adversarial additions. Our experiments show that the proposed strategies outperform the state-ofart data poisoning attacks on KGE models and improve the MRR degradation due to the attacks by up to 62% over the baselines.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers7
- Complex Query Answering on Eventuality Knowledge Graph with Implicit Logical ConstraintsJiaxin Bai, Xin Liu, Weiqi Wang, Chen Luo et al.NeurIPS 2023 · 46 citations
- Poisoning Attack on Federated Knowledge Graph EmbeddingEnyuan Zhou, Song Guo, Zhixiu Ma, Zicong Hong et al.WWW 2024 · 6 citations
- Untargeted Adversarial Attack on Knowledge Graph EmbeddingsTianzhe Zhao, Jiaoyan Chen, Yanchi Ru, Qika Lin et al.SIGIR 2024 · 5 citations
- eXpath: Explaining Knowledge Graph Link Prediction with Ontological Closed Path RulesYe Sun, Lei Shi, Yongxin TongVLDB 2025 · 3 citations
- DRGW: Learning Disentangled Representations for Robust Graph WatermarkingJiasen Li, Yanwei Liu, Zhuoyi Shang, Xiaoyan Gu et al.WWW 2026 · 3 citations
Builds on8
- Estimating Training Data Influence by Tracing Gradient DescentGarima Pruthi, Frederick Liu, Satyen Kale, Mukund SundararajanNeurIPS 2020 · 784 citations
- You CAN Teach an Old Dog New Tricks! On Training Knowledge Graph EmbeddingsDaniel Ruffinelli, Samuel Broscheit, Rainer GemullaICLR 2020 · 238 citations
- Explaining Black Box Predictions and Unveiling Data Artifacts through Influence FunctionsXiaochuang Han, Byron C. Wallace, Yulia TsvetkovACL 2020 · 91 citations
- Evaluation of Similarity-based ExplanationsKazuaki Hanawa, Sho Yokoi, Satoshi Hara, Kentaro InuiICLR 2021 · 79 citations
- On Second-Order Group Influence Functions for Black-Box PredictionsSamyadeep Basu, Xuchen You, Soheil FeiziICML 2020 · 28 citations
Related papers
- Poisoning Knowledge Graph Embeddings via Relation Inference PatternsPeru Bhardwaj, John D. Kelleher, Luca Costabello, Declan O'SullivanACL 2021
- MaSS: Model-agnostic, Semantic and Stealthy Data Poisoning Attack on Knowledge Graph EmbeddingXiaoyu You, Beina Sheng, Daizong Ding, Mi Zhang et al.WWW 2023 · 12 citations
- Debiasing knowledge graph embeddingsJoseph Fisher, Arpit Mittal, Dave Palfrey, Christos ChristodoulopoulosEMNLP 2020 · 40 citations
- Unveiling and Mitigating Untargeted Poisoning Attacks on Federated Knowledge Graph EmbeddingWenzheng Jiang, Ke Liang, Wenke Huang, Xiongtao Zhang et al.WWW 2026
- Jointly Attacking Graph Neural Network and its ExplanationsWenqi Fan, Han Xu, Wei Jin, Xiaorui Liu et al.ICDE 2023 · 23 citations
