Poisoning medical knowledge using large language models
Yang, J.; Xu, H.; Mirzoyan, S.; Chen, T.; Liu, Z.; Ju, W.; Liu, L.; Zhang, M.; Wang, S.
Show abstract
Biomedical knowledge graphs constructed from scientific literature have been widely used to validate biological discoveries and generate new hypotheses. Recently, large language models (LLMs) have demonstrated a strong ability to generate human-like text data. While most of these text data have been useful, LLM might also be used to generate malicious content. Here, we investigate whether it is possible that a malicious actor can use LLM to generate a malicious paper that poisons scientific knowledge graphs and further affects downstream biological applications. As a proof-of-concept, we develop Scorpius, a conditional text generation model that generates a malicious paper abstract conditioned on a promoting drug and a target disease. The goal is to fool the knowledge graph constructed from a mixture of this malicious abstract and millions of real papers so that knowledge graph consumers will misidentify this promoting drug as relevant to the target disease. We evaluated Scorpius on a knowledge graph constructed from 3,818,528 papers and found that Scorpius can increase the relevance of 71.3% drug disease pairs from the top 1000 to the top 10 by only adding one malicious abstract. Moreover, the generation of Scorpius achieves better perplexity than ChatGPT, suggesting that such malicious abstracts cannot be efficiently detected by humans. Collectively, Scorpius demonstrates the possibility of poisoning scientific knowledge graphs and manipulating downstream applications using LLMs, indicating the importance of accountable and trustworthy scientific knowledge discovery in the era of LLM.
Matching journals
The top 8 journals account for 50% of the predicted probability mass.
Similar papers in this journal
- Building A Unified Model for Drug Synergy Analysis Powered by Large Language Models 94%
- scDisInFact: disentangled learning for integration and prediction of multi-batch multi-condition single-cell RNA-sequencing data 94%
- GRouNdGAN: GRN-guided simulation of single-cell RNA-seq data using causal generative adversarial networks 94%
Similar papers in this journal
Similar papers in this journal
- scELMo: Embeddings from Language Models are Good Learners for Single-cell Data Analysis 95%
- Discovering nuclear localization signal universe through a novel deep learning model with interpretable attention units 94%
- Generating hard-to-obtain information from easy-to-obtain information: applications in drug discovery and clinical inference 94%
"Similar papers" are the closest papers from that journal in the model's embedding space. They show what the match is built on, but the ranking comes mostly from a classifier over the whole training set, not from these examples alone.