acceptodds
Under review as a conference paper at ICLR 2027

TopoPoison: Topological Poisoning Attacks on Graph Retrieval-Augmented Generation

Abstract

Graph Retrieval-Augmented Generation (GraphRAG) enhances the ability of large language models to integrate knowledge across documents and answer multi-hop questions by organizing unstructured corpora into entities, relations and higher-level graph structures. However, its continued reliance on external knowledge sources also introduces new data poisoning risks. Existing poisoning methods developed for conventional RAG do not readily transfer to GraphRAG, as its structured processing transforms injected text into graph representations and changes how poisoned knowledge is retrieved. In GraphRAG, successful targeted poisoning involves three successive challenges: preserving the poisoned knowledge during structured indexing, ensuring its retrieval for the target query, and inducing the attacker-specified answer despite competing evidence during answer generation. Black-box settings further compound these challenges by limiting the attacker's visibility into the internal knowledge graph and retrieval structures, making it more difficult to identify and manipulate query-relevant reasoning structures. To address these challenges, we propose TopoPoison, a black-box, append-only targeted data poisoning framework for GraphRAG. TopoPoison follows a three-stage pipeline: it first recovers an approximate query-relevant graph from victim feedback, organizes recovered reasoning paths into candidate-specific subgraphs, and estimates the structural support of each candidate; it then uses these structures to reinforce the attacker-specified answer and redirect selected competitors based on the estimated structural support; finally, it realizes the planned structural interventions as coherent poisoning documents with high indexing fidelity and retrieval reachability. Experimental results show that TopoPoison consistently outperforms representative GraphRAG poisoning baselines across different datasets and victim systems, demonstrating the feasibility of black-box targeted data poisoning using only query feedback and revealing potential poisoning risks in the external knowledge ingestion process of GraphRAG.

Then back it, or bet against it.

Related papers

Open the market on this paper to see 7 more related papers.