Independent research: GraphRAG makes AI agents 80% more truthful | Read the report

NODES 26 — November 12, 2026

Structure Is Not Security: Poisoning Graph-Based Agent Memory Through the Extraction Pipeline

Session track: Modern Applications

Session time:

Session description:

Knowledge graphs are becoming the memory layer of AI agents — text promoted into typed, embedded, retrievable nodes the agent later trusts. Their promise is structure: schema, typing, ontology validation. This talk argues that the structure is the attack surface, and that the layer where defenses usually live — the database — is the wrong place to look. Using a reproducible proof-of-concept against a graph-backed agent memory system, I trace a kill chain that ends with an agent acting on attacker-controlled "knowledge," and threat-model why structural validation gives false assurance and where defense actually has to move. If you build or deploy graph-backed AI, you'll leave with a threat model you didn't have.

Speaker

photo of Ramona Truta

Ramona Truta

Independent AI Security Researcher · Adversarial agentic AI · Structure is not security

Ramona Truta is an independent AI security researcher who builds instruments to prove agentic-AI failure modes are systemic, not edge cases. Bringing 20+ years of database engineering to generative AI, she designs reproducible, temperature-0 adversarial harnesses that surface semantic vulnerabilities and document them with full provenance. That rigor is codified in sqlbenchdag, her open-source lab where every result is content-addressed, integrity-sealed and timestamped — verifiable without trusting the researcher who ran it. Her research spans graph-memory poisoning, and multi-agent social-signal cascades. Three axioms drive her: structure is not security; context is empathy; context is fractal.