acceptodds
Under review as a conference paper at ICLR 2027

Hardening GraphRAG Against Poisoning Across the Knowledge Lifecycle

Abstract

Graph retrieval-augmented generation (GraphRAG) constructs knowledge graphs (KGs) from external corpora to provide structured knowledge for large language models (LLMs), improving factual accuracy and knowledge utilization. However, recent studies have shown that GraphRAG is vulnerable to poisoning attacks, where attackers inject malicious texts into the external corpus to contaminate the KG and manipulate responses to target queries. Existing defenses are largely designed for conventional RAG or focus on repairing already-poisoned KG, leaving the broader poisoning process insufficiently protected. In this paper, we propose SafeG, a novel poisoning defense framework for GraphRAG that spans both KG evolution and KG-based inference. During KG evolution, SafeG quantifies the structural deviation induced by each incoming document through changes in KG information propagation and filters anomalous content. During inference, SafeG constructs multi-granularity evidence views under different retrieval budgets and generates candidate responses, followed by LLM-based credibility verification for robust response selection. Extensive experiments across multiple datasets, frameworks, and LLMs demonstrate that SafeG consistently improves accuracy while reducing attack success rates against GraphRAG poisoning. Overall, SafeG provides an effective lifecycle-oriented defense against structural contamination in GraphRAG.

Then back it, or bet against it.

Related papers

Open the market on this paper to see 7 more related papers.