Researchers poison their own data when stolen by an AI to ruin results

  • Researchers from China and Singapore proposed AURA (Active Utility Reduction via Adulteration) to protect GraphRAG systems
  • AURA deliberately poisons proprietary knowledge graphs so stolen data produces hallucinations and wrong answers
  • Correct outputs require a secret key; tests showed ~94% effectiveness in degrading stolen KG utility

Researchers from universities in China and Singapore came up with a creative way to prevent the theft of data used in Generative AI.

Among other things, there are two important elements in today’s Large Language Models (LLM): training data, and retrieval-augmented generation (RAG).

Training data teaches an LLM how language works and gives it broad knowledge up to a cutoff point. It doesn’t give the model access to new information, private documents, or fast-changing facts. Once training is done, that knowledge is frozen.

Replacing outdated gear

RAG, on the other hand, exists because many real questions depend on current, specific, or proprietary data (such as company policies, recent news, internal reports, or niche technical documents). Instead of retraining the model every time data changes, RAG lets the model fetch relevant information on demand and then write an answer based on it.

In 2024, Microsoft came up with GraphRAG – a version of RAG that organizes retrieved information as a knowledge graph instead of a flat list of documents. This helps the model understand how entities, facts, and relationships connect to each other. As a result, the AI can answer more complex questions, follow links between concepts, and reduce contradictions by reasoning over structured relationships rather than isolated text.

Since these knowledge graphs can be rather expensive, they could be targeted by cybercriminals, nation-states, and other malicious entities.

In their research paper, titled Making Theft Useless: Adulteration-Based Protection of Proprietary Knowledge Graphs in GraphRAG Systems, authors Weijie Wang, Peizhuo Lv, et al. proposed a defense mechanism called Active Utility Reduction via Adulteration, or AURA – which poisons the KGs, making the LLM give wrong answers and hallucinate.

The only way to get correct answers is to have a secret key. The researchers said the system is not without its flaws, but that it works great in most cases (94%).

“By degrading the stolen KG’s utility, AURA offers a practical solution for protecting intellectual property in GraphRAG,” the authors stated.

Via The Register

Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds. Make sure to click the Follow button!

And of course you can also follow TechRadar on TikTok for news, reviews, unboxings in video form, and get regular updates from us on WhatsApp too.

Read more @ TechRadar

Latest posts

Fulham vs Chelsea Live Streams: How to Watch Premier League 2025-26 From Anywhere in the World

Fulham vs Chelsea: Wednesday, Jan. 7 at 7.30pm GMT / 2.30pm ET Stream on Sky Sports (UK) or Peacock (US)Access your usual streaming services...

Here are 13 TV deals I’d buy in the new year — clearance prices starting at just $69.99

New year, new you... new TV? If you want to start 2026 with a brand-new display, I'm here to help. As TechRadar's deals editor...

New Virginia teen safety law sparks privacy debate and fresh legal challenges

New social media rules came into effect in Virginia on January 1stPlatforms must limit data collection and restrict screen time for under-18sNetChoice is challenging...

Pakistan begins blocking unregistered VPN apps – and this popular service is among the casualties

Pakistan has reportedly begun to block unregistered VPNsProton said its apps have been restricted since December 22Pakistan resumed VPN licensing in NovemberPakistan has long...

Hurry! ESET’s holiday discount ends soon – save up to 33% off antivirus plans

As we usher in the new year, you might have a host of new devices that need antivirus protection. Luckily for you, there are...

Can RGB mini-LED dethrone OLED? Here’s what it needs to do

OLED has been at the very top of the TV market for several years now and is arguably the most popular of panel technologies....

This IKEA speaker is tiny, insanely cheap, and I want 100 of them

IKEA's Sonos partnership is overIt's not done with audioIt unveiled a tiny new $10 speakerIKEA’s Sonos partnership, the one that helped create the eye-catching...

Burnley vs Man Utd Free Streams: How to Watch Premier League 2025-26 From Anywhere in the World, Team News

Burnley vs Man Utd: Wednesday Jan. 7 at 8:15pm GMT / 3:15pm ETStream on USA Network via YouTube TV (try it free)(US)Access your usual...

The 7 weirdest gadgets we’ve seen at CES 2026 – from a musical popsicle to headphones with eyes

CES 2026 has its fair share of weird tech announcements, and while we've been excited to see what tech giants such as Samsung, Amazon,...

Dell New Year sale slashes up to $500 off laptops — here are the 5 best deals from $299.99

Dell has kicked off January with a New Year sale across several of its newest and top-rated laptops. As one of the manufacturers I...