Poisoning Attack on Federated Knowledge Graph Embedding
Enyuan Zhou, Song Guo, Zhixiu Ma, Zicong Hong, Tao Guo, Peiran Dong
Abstract
Federated Knowledge Graph Embedding (FKGE) is an emerging collaborative learning technique for deriving expressive representations (i.e., embeddings) from client-maintained distributed knowledge graphs (KGs). However, poisoning attacks in FKGE, which lead to biased decisions by downstream applications, remain unexplored. This paper is the first work to systematise the risks of FKGE poisoning attacks, from which we develop a novel framework for poisoning attacks that force the victim client to predict specific false facts. The challenge is that FKGE maintains KGs for training locally on clients, preventing attackers in centralized KGEs from injecting poisoned data directly into the victim's training data. Thus, an attacker needs to create poisoned data without the victim's local KG, and inject the poisoned data indirectly into the victim's embeddings via FKGE aggregation. Specifically, to create poisoned data, the attacker first infers the targeted relations in the victim's local KG via a new KG component inference attack. Then, to accurately mislead the victim's embeddings via aggregation, the attacker locally trains a shadow model using the poisoned data and uses an optimised dynamic poisoning scheme to adjust the model and generate progressive poisoned updates. Our experimental results demonstrate the attack's effectiveness, achieving a remarkable success rate on various KGE models (e.g. 100% on TransE with WNRR), while keeping the original task's performance nearly unchanged.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext d92a3301-74dc-4b55-b676-8f0787f56611Cited by top-tier papers3
- GraphRAG Under FireJiacheng Liang, Yuhui Wang, Changjiang Li, Tanqiu Jiang et al.S&P 2026 · 31 citations
- Learning to Evolve: Bayesian-Guided Continual Knowledge Graph EmbeddingLinYu Li, Zhi Jin, Yuanpeng He, Dongming Jin et al.WWW 2026 · 1 citation
- Has the Two-Decade-Old Prophecy Come True? Artificial Bad Intelligence Triggered by Merely a Single-Bit Flip in Large Language ModelsYu Yan, Siqi Lu, Yang Gao, Zhaoxuan Li et al.WWW 2026 · 1 citation
Builds on27
- Deep Learning with Differential PrivacyMartín Abadi, Andy Chu, Ian J. Goodfellow, H. Brendan McMahan et al.CCS 2016 · 7,620 citations
- Knowledge Graph Contrastive Learning for RecommendationYuhao Yang, Chao Huang, Lianghao Xia, Chenliang LiSIGIR 2022 · 487 citations
- Fast Private Set Intersection from Homomorphic EncryptionHao Chen, Kim Laine, Peter RindalCCS 2017 · 446 citations
- LIRA: Learnable, Imperceptible and Robust Backdoor AttacksKhoa D. Doan, Yingjie Lao, Weijie Zhao, Ping LiICCV 2021 · 313 citations
- Practical Multi-party Private Set Intersection from Symmetric-Key TechniquesVladimir Kolesnikov, Naor Matania, Benny Pinkas, Mike Rosulek et al.CCS 2017 · 247 citations
Related papers
- Quantifying and Defending against Privacy Threats on Federated Knowledge Graph EmbeddingYuke Hu, Wei Liang, Ruofan Wu, Kai Xiao et al.WWW 2023 · 21 citations
- Unveiling and Mitigating Untargeted Poisoning Attacks on Federated Knowledge Graph EmbeddingWenzheng Jiang, Ke Liang, Wenke Huang, Xiongtao Zhang et al.WWW 2026
- Poisoning Knowledge Graph Embeddings via Relation Inference PatternsPeru Bhardwaj, John D. Kelleher, Luca Costabello, Declan O'SullivanACL 2021
- MaSS: Model-agnostic, Semantic and Stealthy Data Poisoning Attack on Knowledge Graph EmbeddingXiaoyu You, Beina Sheng, Daizong Ding, Mi Zhang et al.WWW 2023 · 12 citations
- Adversarial Attacks on Knowledge Graph Embeddings via Instance Attribution MethodsPeru Bhardwaj, John D. Kelleher, Luca Costabello, Declan O'SullivanEMNLP 2021 · 17 citations
