Oracle Poisoning: New Attack Vector Corrupts Knowledge Graphs to Manipulate AI Agents
Researchers have identified a new cybersecurity threat termed 'Oracle Poisoning,' where adversaries corrupt structured knowledge graphs queried by AI agents at runtime. Unlike prompt injection, which manipulates instructions, this attack alters the underlying data, causing AI models to draw incorrect conclusions through logically correct reasoning. The study, published on arXiv, demonstrates six attack scenarios against a production-scale code knowledge graph containing 42 million nodes. Empirical tests across nine AI models from three providers revealed that at moderate attacker sophistication, every model trusted poisoned data with 100% certainty under directed queries. The research highlights that inline evaluation methods often produce false negatives, failing to detect vulnerabilities present in real agentic tool-use scenarios. While read-only access controls effectively eliminate the direct mutation vector, other defenses remain partial and model-dependent. The findings suggest that Oracle Poisoning may generalize across the broader knowledge-graph ecosystem, posing significant risks to autonomous AI systems relying on external data sources for decision-making and reasoning processes.
Wire timeline
Oracle Poisoning: New Attack Vector Corrupts Knowledge Graphs to Manipulate AI Agents
Researchers have identified a new cybersecurity threat termed 'Oracle Poisoning,' where adversaries corrupt structured knowledge graphs queried by AI agents at runtime. Unlike prompt injection, which manipulates instructions, this attack alters the underlying data, causing AI models to draw incorrect conclusions through logically correct reasoning. The study, published on arXiv, demonstrates six attack scenarios against a production-scale code knowledge graph containing 42 million nodes. Empirical tests across nine AI models from three providers revealed that at moderate attacker sophistication, every model trusted poisoned data with 100% certainty under directed queries. The research highlights that inline evaluation methods often produce false negatives, failing to detect vulnerabilities present in real agentic tool-use scenarios. While read-only access controls effectively eliminate the direct mutation vector, other defenses remain partial and model-dependent. The findings suggest that Oracle Poisoning may generalize across the broader knowledge-graph ecosystem, posing significant risks to autonomous AI systems relying on external data sources for decision-making and reasoning processes.
cs.AI updates on arXiv.org