← Back to search
paper llmsec-2026-00105

Oracle Poisoning: Corrupting Knowledge Graphs to Weaponise AI Agent Reasoning

Ben Kereopa-Yorke, Guillermo Diaz, Holly Wright, Reagan Johnston, Ron F. Del Rosario, Timothy Lynar

2026-05

Abstract

We define Oracle Poisoning, an attack class in which an adversary corrupts a structured knowledge graph that AI agents query at runtime via tool-use protocols, causing incorrect conclusions through correct reasoning. Unlike prompt injection, Oracle Poisoning manipulates the data agents reason over, not their instructions. We demonstrate six attack scenarios against a production 42-million-node code knowledge graph, providing the first empirical demonstration of knowledge graph poisoning against

Cite This Resource

@article{llmsec202600105,
  title = {Oracle Poisoning: Corrupting Knowledge Graphs to Weaponise AI Agent Reasoning},
  author = {Ben Kereopa-Yorke and Guillermo Diaz and Holly Wright and Reagan Johnston and Ron F. Del Rosario and Timothy Lynar},
  year = {2026},
  url = {https://arxiv.org/abs/2605.09822},
}

Metadata

Added
2026-05-17
Added by
automation
Source
arxiv
arxiv_id
2605.09822