Hop-Decayed Influence: New Vulnerabilities of Structural Auxiliary Indexing in GraphRAG Pipelines with LLM

📅 2026-10-01
📈 Citations: 0
✨ Influential: 0
📄 PDF
🤖 AI Summary
This study addresses the unverified trust blind spots in GraphRAG auxiliary index structures, which render them vulnerable to malicious attacks. We formally identify schema-level auxiliary entities as an attack surface for the first time, proposing a systematic exploitation framework termed 3S and a corresponding Hijacking via Data Injection (HDI) method. By leveraging query-aware influence propagation and post-processing tampering of auxiliary structures, our approach achieves high-leverage impact at minimal cost. Experiments on two major benchmarks demonstrate attack success rates of 88–94%, requiring modifications to merely 0.016% of the structure while exceeding a 99% defense evasion rate. This work reveals structural vulnerabilities enabling GraphRAG to bypass linguistic defenses, establishing a new paradigm for security evaluation in this domain.
📝 Abstract
GraphRAG pipelines construct auxiliary structures during offline indexing--semantic summaries, hierarchical edges, and pre-computed scores--that determine how retrieval is prioritised at query time. Prior attacks target only instance-level components (nodes, edges, triples), overlooking these schema-level structures. We formalise Auxiliary Schema-Level Entity as a novel attack surface and propose the 3S Framework (Semantics, Structure, Scoring) for its systematic exploitation. Our Hop-Decayed Influence (HDI) attack identifies high-impact targets through query-aware influence propagation and corrupts their auxiliary structures post-indexing. Across two benchmarks (HotpotQA, 2WikiMultiHopQA) and two architectures (Microsoft GraphRAG, HippoRAG2), HDI achieves 88-94% attack success rate while modifying as few as 0.016% of auxiliary structures. Each modification affects up to 6.00 queries (Schema Leverage Ratio), demonstrating 1:N amplification unavailable to instance-level attacks. Manipulated structures evade perplexity and paraphrase defenses with over 99% evasion rate, as they remain linguistically coherent system-generated artifacts. These results reveal that auxiliary schema-level entities receive implicit trust without runtime validation, constituting a structural blind spot in current GraphRAG defenses. https://github.com/Jisung-Pacific/HDI-GraphRAG-Attack.
Problem

Research questions and friction points this paper is trying to address.

GraphRAG
auxiliary indexing
schema-level vulnerability
security attack
large language models
Innovation

Methods, ideas, or system contributions that make the work stand out.

GraphRAG
Hop-Decayed Influence
Auxiliary Schema-Level Entity
3S Framework
Adversarial Attack
Jisung Park
Jisung Park
Dept. of Computer Science and Engineering, POSTECH
computer architecturesystem softwarememory systemsstorage systemssystem security
J
John Le
Institute of Cybersecurity and Cryptology, University of Wollongong
H
Heath Cooper
Institute of Cybersecurity and Cryptology, University of Wollongong