跳到正文
arXiv:cs.AI· Jisung Park, John Le, Heath Cooper·· 4 小时前AI 评分64

HDI 攻击揭示 GraphRAG 辅助索引结构的 Schema 级安全漏洞

Hop-Decayed Influence: New Vulnerabilities of Structural Auxiliary Indexing in GraphRAG Pipelines with LLM

AI 导读

论文提出 Hop-Decayed Influence(HDI)攻击,将 GraphRAG 离线索引构建的 schema 级辅助结构(语义摘要、层级边、预计算分数)形式化为新攻击面,并提出 3S 框架(Semantics、Structure、Scoring)加以利用。

正文

View PDF HTML (experimental)

Abstract:GraphRAG pipelines construct auxiliary structures during offline indexing--semantic summaries, hierarchical edges, and pre-computed scores--that determine how retrieval is prioritised at query time. Prior attacks target only instance-level components (nodes, edges, triples), overlooking these schema-level structures. We formalise Auxiliary Schema-Level Entity as a novel attack surface and propose the 3S Framework (Semantics, Structure, Scoring) for its systematic exploitation. Our Hop-Decayed Influence (HDI) attack identifies high-impact targets through query-aware influence propagation and corrupts their auxiliary structures post-indexing. Across two benchmarks (HotpotQA, 2WikiMultiHopQA) and two architectures (Microsoft GraphRAG, HippoRAG2), HDI achieves 88-94% attack success rate while modifying as few as 0.016% of auxiliary structures. Each modification affects up to 6.00 queries (Schema Leverage Ratio), demonstrating 1:N amplification unavailable to instance-level attacks. Manipulated structures evade perplexity and paraphrase defenses with over 99% evasion rate, as they remain linguistically coherent system-generated artifacts. These results reveal that auxiliary schema-level entities receive implicit trust without runtime validation, constituting a structural blind spot in current GraphRAG defenses. this https URL.
Comments: 14 pages. Published in IFIP SEC 2026. Best Paper Award
Subjects: Cryptography and Security (cs.CR); Artificial Intelligence (cs.AI)
Cite as: arXiv:2610.02373 [cs.CR]
  (or arXiv:2610.02373v1 [cs.CR] for this version)
  https://doi.org/10.48550/arXiv.2610.02373

arXiv-issued DOI via DataCite (pending registration)

Journal reference: ICT Systems Security and Privacy Protection (SEC 2026), IFIP Advances in Information and Communication Technology, vol. 787, pp. 345-358, Springer (2026)
Related DOI: https://doi.org/10.1007/978-3-032-27993-4_24

DOI(s) linking to related resources

Submission history

From: Jisung Park [view email]
[v1] Thu, 1 Oct 2026 18:52:10 UTC (113 KB)

来源:arXiv:cs.AI · arxiv.org