Skip to content

Latest commit

 

History

3 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 

Repository files navigation

Hop-Decayed Influence: New Vulnerabilities of Structural Auxiliary Indexing in GraphRAG Pipelines with LLM

Jisung Park, John Le, Heath Cooper
Institute of Cybersecurity and Cryptology (iC²), University of Wollongong
IFIP SEC 2026


jspacific0307/HDI-graphragpipeline https://huggingface.co/datasets/jspacific0307/HDI-graphragpipeline

Overview

GraphRAG pipelines construct auxiliary structures during offline indexing — semantic summaries, hierarchical edges, and pre-computed scores — that existing attacks completely overlook.

This paper formalises Auxiliary Schema-Level Entity as a novel attack surface and proposes:

  • 3S Framework: Semantics, Structure, Scoring attacks
  • Hop-Decayed Influence (HDI): A gray-box target selection algorithm using BFS-based influence propagation with exponential decay

Key Results

Metric Value
Attack Success Rate (ASR) 88%+ across all configurations
Modification Ratio as low as 0.016% of total structures
Schema Leverage Ratio (SLR) up to 6.00 (queries affected per modification)
Perplexity Filter Evasion 99.5%+
Paraphrase Defense Evasion 99.1%+

Attack Pipeline

Query → Entity Extraction → KG Mapping → HDI Target Selection → 3S Attack
  1. Query entity extraction — extract seed entities from target queries
  2. KG mapping — map seeds to graph nodes
  3. HDI target selection — BFS-based influence propagation with decay factor λ
  4. 3S attack — apply Semantic / Structure / Score attack on selected targets

3S Framework

Attack Target Method
Semantic (S) Textual summaries Inject adversarial text with low perplexity
Structure (T) Hierarchical edges Add misleading edges to semantically distant nodes
Score (C) Pre-computed scores Demote high-ranked nodes, promote irrelevant ones

Hop-Decayed Influence (HDI)

Influence propagates from seed entities with exponential decay by hop distance:

$$\text{Influence}(v) = \sum_{q \in Q} \sum_{s \in \text{Seeds}(q)} \lambda^{d(s,v)}$$

  • λ ∈ (0, 1): decay factor (default: 0.5)
  • hmax: maximum hop distance (default: 4)
  • Top-k nodes selected as attack targets

Experimental Setup

Baselines

  • Microsoft GraphRAG (hierarchical community detection)
  • HippoRAG2 (Personalised PageRank)

Datasets

  • HotpotQA (1,000 samples)
  • 2WikiMultiHopQA (1,000 samples)

Models

  • text-embedding-3-small (OpenAI)
  • GPT-4o-mini (OpenAI)

Results Summary

System Dataset Best Config ASR (%) Mod. Ratio (%) SLR
MS GraphRAG HotpotQA HDI-T 91.69 4.74 4.57
MS GraphRAG 2WikiMHQA HDI-T 88.17 4.82 3.41
HippoRAG2 HotpotQA HDI-T 88.24 0.075 5.80
HippoRAG2 2WikiMHQA HDI-C 94.44 0.016 6.00

Installation

git clone https://github.com/Jisung-Pacific/HDI-GraphRAG-Attack
cd HDI-GraphRAG-Attack
pip install -r requirements.txt

Citation

@inproceedings{park2026hdi,
  title     = {Hop-Decayed Influence: New Vulnerabilities of Structural Auxiliary Indexing in GraphRAG Pipelines with LLM},
  author    = {Park, Jisung and Le, John and Cooper, Heath},
  booktitle = {IFIP International Information Security and Privacy Conference (SEC)},
  year      = {2026}
}

Ethical Consideration

All experiments were conducted on public benchmark datasets and open-source implementations in isolated environments. No attacks targeted production systems. Findings were shared with affected project maintainers prior to publication.

About

No description, website, or topics provided.

Resources

Stars

1 star

Watchers

0 watching

Forks

Releases

Packages

Contributors