May 2026Unreviewed
Oracle Poisoning: Corrupting Knowledge Graphs to Weaponise AI Agent Reasoning
Ben Kereopa-Yorke, Guillermo Diaz, Holly Wright, Reagan Johnston, Ron F. Del Rosario, Timothy Lynar
Abstract
We define Oracle Poisoning, an attack class in which an adversary corrupts a structured knowledge graph that AI agents query at runtime via tool-use protocols, causing incorrect conclusions through correct reasoning. Unlike prompt injection, Oracle Poisoning manipulates the data agents reason over, not their instructions. We demonstrate six attack scenarios against a production 42-million-node code knowledge graph, providing the first empirical demonstration of knowledge graph poisoning against
Categories
Framework mappings
OWASP Top 10 for LLM Applications
- LLM01Prompt Injection
MITRE ATLAS
- AML.T0051LLM Prompt Injection
Suggested from the entry's categories.
Cite
@misc{kereopayorke2026oracle,
title = {{Oracle Poisoning: Corrupting Knowledge Graphs to Weaponise AI Agent Reasoning}},
author = {Ben Kereopa-Yorke and Guillermo Diaz and Holly Wright and Reagan Johnston and Ron F. Del Rosario and Timothy Lynar},
year = {2026},
month = may,
eprint = {2605.09822},
archivePrefix = {arXiv},
url = {https://arxiv.org/abs/2605.09822}
}