arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2610.02373cs.CRcs.AI

Hop-Decayed Influence: GraphRAG 流水线中结构辅助索引的新漏洞(LLM)

Hop-Decayed Influence: New Vulnerabilities of Structural Auxiliary Indexing in GraphRAG Pipelines with LLM

Jisung Park, John Le, Heath Cooper

首次发表
浏览论文内容

中文总结 AI 辅助

针对 GraphRAG 流水线中辅助模式级结构的新攻击面,提出 Hop-Decayed Influence 攻击,通过查询感知影响传播破坏少量结构,实现高成功率与 1:N 放大效应,揭示防御盲点。

中文摘要 AI 辅助

GraphRAG 流水线在离线索引期间构建辅助结构——语义摘要、分层边和预计算分数——这些结构决定了查询时检索的优先级。先前的攻击仅针对实例级组件(节点、边、三元组),忽视了这些模式级结构。我们将辅助模式级实体形式化为一种新的攻击面,并提出 3S 框架(语义、结构、评分)用于其系统性利用。我们的 Hop-Decayed Influence(HDI)攻击通过查询感知的影响传播识别高影响目标,并在索引后破坏其辅助结构。在两个基准(HotpotQA、2WikiMultiHopQA)和两种架构(Microsoft GraphRAG、HippoRAG2)上,HDI 实现了 88-94% 的攻击成功率,同时仅修改了 0.016% 的辅助结构。每次修改影响多达 6.00 个查询(模式杠杆率),展示了实例级攻击无法实现的 1:N 放大效应。被操纵的结构以超过 99% 的规避率逃避困惑度和释义防御,因为它们仍然是语言连贯的系统生成工件。这些结果表明,辅助模式级实体在运行时验证中受到隐式信任,构成了当前 GraphRAG 防御中的结构性盲点。此 https URL。

英文摘要

GraphRAG pipelines construct auxiliary structures during offline indexing--semantic summaries, hierarchical edges, and pre-computed scores--that determine how retrieval is prioritised at query time. Prior attacks target only instance-level components (nodes, edges, triples), overlooking these schema-level structures. We formalise Auxiliary Schema-Level Entity as a novel attack surface and propose the 3S Framework (Semantics, Structure, Scoring) for its systematic exploitation. Our Hop-Decayed Influence (HDI) attack identifies high-impact targets through query-aware influence propagation and corrupts their auxiliary structures post-indexing. Across two benchmarks (HotpotQA, 2WikiMultiHopQA) and two architectures (Microsoft GraphRAG, HippoRAG2), HDI achieves 88-94% attack success rate while modifying as few as 0.016% of auxiliary structures. Each modification affects up to 6.00 queries (Schema Leverage Ratio), demonstrating 1:N amplification unavailable to instance-level attacks. Manipulated structures evade perplexity and paraphrase defenses with over 99% evasion rate, as they remain linguistically coherent system-generated artifacts. These results reveal that auxiliary schema-level entities receive implicit trust without runtime validation, constituting a structural blind spot in current GraphRAG defenses. https://github.com/Jisung-Pacific/HDI-GraphRAG-Attack.

发表机构

  • University of Wollongong(伍伦贡大学)

机构由 AI 辅助整理,请以论文原文为准。

补充信息

↑