Skip to content
Search
paperMay 2026Unreviewed

BadSKP: Backdoor Attacks on Knowledge Graph-Enhanced LLMs with Soft Prompts

Xiaoting Lyu, Yufei Han, Hangwei Qian, Haoyuan Yu, Xiang Ao, Bin Wang, Chenxu Wang, Xiaobo Ma, Wei Wang

Abstract

Recent knowledge graph (KG)-enhanced large language models (LLMs) move beyond purely textual knowledge augmentation by encoding retrieved subgraphs into continuous soft prompts via graph neural networks, introducing a graph-conditioned channel that operates alongside the standard text interface. However, existing backdoor attacks are largely designed for the textual channel, and their effectiveness against this dual-channel architecture remains unclear. We show that this architecture creates a r

Categories

Framework mappings

OWASP Top 10 for LLM Applications
  • LLM04Data and Model Poisoning
MITRE ATLAS
  • AML.T0020Poison Training Data

Suggested from the entry's categories.

Cite

@misc{lyu2026badskp,
  title = {{BadSKP: Backdoor Attacks on Knowledge Graph-Enhanced LLMs with Soft Prompts}},
  author = {Xiaoting Lyu and Yufei Han and Hangwei Qian and Haoyuan Yu and Xiang Ao and Bin Wang and Chenxu Wang and Xiaobo Ma and Wei Wang},
  year = {2026},
  month = may,
  eprint = {2605.11996},
  archivePrefix = {arXiv},
  url = {https://arxiv.org/abs/2605.11996}
}