Poisoning Attack on Federated Knowledge Graph Embedding
Enyuan Zhou, Song Guo, Zhixiu Ma, Zicong Hong, Tao Guo, Peiran Dong
摘要
Federated Knowledge Graph Embedding (FKGE) is an emerging collaborative learning technique for deriving expressive representations (i.e., embeddings) from client-maintained distributed knowledge graphs (KGs). However, poisoning attacks in FKGE, which lead to biased decisions by downstream applications, remain unexplored. This paper is the first work to systematise the risks of FKGE poisoning attacks, from which we develop a novel framework for poisoning attacks that force the victim client to predict specific false facts. The challenge is that FKGE maintains KGs for training locally on clients, preventing attackers in centralized KGEs from injecting poisoned data directly into the victim's training data. Thus, an attacker needs to create poisoned data without the victim's local KG, and inject the poisoned data indirectly into the victim's embeddings via FKGE aggregation. Specifically, to create poisoned data, the attacker first infers the targeted relations in the victim's local KG via a new KG component inference attack. Then, to accurately mislead the victim's embeddings via aggregation, the attacker locally trains a shadow model using the poisoned data and uses an optimised dynamic poisoning scheme to adjust the model and generate progressive poisoned updates. Our experimental results demonstrate the attack's effectiveness, achieving a remarkable success rate on various KGE models (e.g. 100% on TransE with WNRR), while keeping the original task's performance nearly unchanged.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper3
- GraphRAG Under FireJiacheng Liang, Yuhui Wang, Changjiang Li, Tanqiu Jiang 等S&P 2026 · 被引用 31 次
- Learning to Evolve: Bayesian-Guided Continual Knowledge Graph EmbeddingLinYu Li, Zhi Jin, Yuanpeng He, Dongming Jin 等WWW 2026 · 被引用 1 次
- Has the Two-Decade-Old Prophecy Come True? Artificial Bad Intelligence Triggered by Merely a Single-Bit Flip in Large Language ModelsYu Yan, Siqi Lu, Yang Gao, Zhaoxuan Li 等WWW 2026 · 被引用 1 次
它引用的顶会 Paper27
- Deep Learning with Differential PrivacyMartín Abadi, Andy Chu, Ian J. Goodfellow, H. Brendan McMahan 等CCS 2016 · 被引用 7,620 次
- Knowledge Graph Contrastive Learning for RecommendationYuhao Yang, Chao Huang, Lianghao Xia, Chenliang LiSIGIR 2022 · 被引用 487 次
- Fast Private Set Intersection from Homomorphic EncryptionHao Chen, Kim Laine, Peter RindalCCS 2017 · 被引用 446 次
- LIRA: Learnable, Imperceptible and Robust Backdoor AttacksKhoa D. Doan, Yingjie Lao, Weijie Zhao, Ping LiICCV 2021 · 被引用 313 次
- Practical Multi-party Private Set Intersection from Symmetric-Key TechniquesVladimir Kolesnikov, Naor Matania, Benny Pinkas, Mike Rosulek 等CCS 2017 · 被引用 247 次
相关 Paper
- Quantifying and Defending against Privacy Threats on Federated Knowledge Graph EmbeddingYuke Hu, Wei Liang, Ruofan Wu, Kai Xiao 等WWW 2023 · 被引用 21 次
- Unveiling and Mitigating Untargeted Poisoning Attacks on Federated Knowledge Graph EmbeddingWenzheng Jiang, Ke Liang, Wenke Huang, Xiongtao Zhang 等WWW 2026
- Poisoning Knowledge Graph Embeddings via Relation Inference PatternsPeru Bhardwaj, John D. Kelleher, Luca Costabello, Declan O'SullivanACL 2021
- MaSS: Model-agnostic, Semantic and Stealthy Data Poisoning Attack on Knowledge Graph EmbeddingXiaoyu You, Beina Sheng, Daizong Ding, Mi Zhang 等WWW 2023 · 被引用 12 次
- Adversarial Attacks on Knowledge Graph Embeddings via Instance Attribution MethodsPeru Bhardwaj, John D. Kelleher, Luca Costabello, Declan O'SullivanEMNLP 2021 · 被引用 17 次
