Abstract
Despite rapid growth in research on AI security and privacy, evidence-backed links between attacks and defenses remain fragmented, making synthesis and audit difficult at scale. In this study, we present a domain-specific AI security knowledge graph (KG) constructed from 780 research papers on model-level attacks and defenses using an ontology-constrained, evidence-gated extraction pipeline. The proposed pipeline (1) distills paper text into structured chunks, (2) extracts typed entities and directed relations from a closed ontology, and (3) admits a triple only when it is supported by within-paper sentence-level provenance (verbatim supporting quotes from the paper), while preserving contradictory claims, e.g.“mitigates” vs. “bypasses” with provenance rather than collapsing them. On a 600-triple pooled-candidate, expert-adjudicated QC set, the extractor achieves 0.92 precision and 0.84 triple-level F1, outperforming by 0.19–0.36 open and scientific information-extraction baselines (OpenIE, SciIE) and slightly improving UIEPrompter-style structured-prompting baseline (0.83 F1), while reducing unsupported edges that could mislead downstream security reasoning. We introduce a mitigation-claim coverage metric defined as Attack–Defense Alignment Score (ADAS), the fraction of attacks with at least one verified, non-conflicted mitigating defense; the graph reaches 0.73, exceeding randomized baselines that preserve node types by 0.13–0.17 and highlighting attacks with sparse verified defenses. In the held-out defense recommendation, top-1 success (Hits@1: fraction of test attacks whose correct defense is ranked first) improves by 19.8 percentage points to 0.39 over the best text-only baseline, and each recommendation includes supporting quotes to enable verification.
| Original language | English |
|---|---|
| Article number | 116492 |
| Number of pages | 22 |
| Journal | Knowledge-Based Systems |
| Volume | 350 |
| Early online date | 1 Jul 2026 |
| DOIs | |
| Publication status | E-pub ahead of print - 1 Jul 2026 |
Keywords
- AI security
- adversarial machine learning
- knowledge graphs
- large language models
Fingerprint
Dive into the research topics of 'A domain-specific knowledge graph for reasoning over AI security threats and defenses'. Together they form a unique fingerprint.Cite this
- APA
- Author
- BIBTEX
- Harvard
- Standard
- RIS
- Vancouver