Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Tools/GitHubGitHub/jisung-pacific/hdi-graphrag-attack
Vulnerability AnalysisData ExfiltrationMachine LearningPapers & ResearchAI SecurityAdversarial Attack
GitHubjisung-pacific/hdi-graphrag-attack

HDI-GraphRAG-Attack

Research implementation of Hop-Decayed Influence (HDI) and the 3S attack framework, exposing structural auxiliary indexing vulnerabilities in GraphRAG pipelines with LLMs.

View Repository
146 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Hop-Decayed Influence: New Vulnerabilities of Structural Auxiliary Indexing in GraphRAG Pipelines with LLM

Jisung Park, John Le, Heath Cooper
Institute of Cybersecurity and Cryptology (iC²), University of Wollongong
IFIP SEC 2026


jspacific0307/HDI-graphragpipeline https://huggingface.co/datasets/jspacific0307/HDI-graphragpipeline

Overview

GraphRAG pipelines construct auxiliary structures during offline indexing — semantic summaries, hierarchical edges, and pre-computed scores — that existing attacks completely overlook.

This paper formalises Auxiliary Schema-Level Entity as a novel attack surface and proposes:

  • 3S Framework: Semantics, Structure, Scoring attacks
  • Hop-Decayed Influence (HDI): A gray-box target selection algorithm using BFS-based influence propagation with exponential decay

Key Results

MetricValue
Attack Success Rate (ASR)88%+ across all configurations
Modification Ratioas low as 0.016% of total structures
Schema Leverage Ratio (SLR)up to 6.00 (queries affected per modification)
Perplexity Filter Evasion99.5%+
Paraphrase Defense Evasion99.1%+

Attack Pipeline

Query → Entity Extraction → KG Mapping → HDI Target Selection → 3S Attack
  1. Query entity extraction — extract seed entities from target queries
  2. KG mapping — map seeds to graph nodes
  3. HDI target selection — BFS-based influence propagation with decay factor λ
  4. 3S attack — apply Semantic / Structure / Score attack on selected targets

3S Framework

AttackTargetMethod
Semantic (S)Textual summariesInject adversarial text with low perplexity
Structure (T)Hierarchical edgesAdd misleading edges to semantically distant nodes
Score (C)Pre-computed scoresDemote high-ranked nodes, promote irrelevant ones

Hop-Decayed Influence (HDI)

Influence propagates from seed entities with exponential decay by hop distance:

$$\text{Influence}(v) = \sum_{q \in Q} \sum_{s \in \text{Seeds}(q)} \lambda^{d(s,v)}$$

  • λ ∈ (0, 1): decay factor (default: 0.5)
  • hmax: maximum hop distance (default: 4)
  • Top-k nodes selected as attack targets

Experimental Setup

Baselines

  • Microsoft GraphRAG (hierarchical community detection)
  • HippoRAG2 (Personalised PageRank)

Datasets

  • HotpotQA (1,000 samples)
  • 2WikiMultiHopQA (1,000 samples)

Models

  • text-embedding-3-small (OpenAI)
  • GPT-4o-mini (OpenAI)

Results Summary

SystemDatasetBest ConfigASR (%)Mod. Ratio (%)SLR
MS GraphRAGHotpotQAHDI-T91.694.744.57
MS GraphRAG2WikiMHQAHDI-T88.174.823.41
HippoRAG2HotpotQAHDI-T88.240.0755.80
HippoRAG22WikiMHQAHDI-C94.440.0166.00

Installation

git clone https://github.com/Jisung-Pacific/HDI-GraphRAG-Attack
cd HDI-GraphRAG-Attack
pip install -r requirements.txt

Citation

@inproceedings{park2026hdi,
  title     = {Hop-Decayed Influence: New Vulnerabilities of Structural Auxiliary Indexing in GraphRAG Pipelines with LLM},
  author    = {Park, Jisung and Le, John and Cooper, Heath},
  booktitle = {IFIP International Information Security and Privacy Conference (SEC)},
  year      = {2026}
}

Ethical Consideration

All experiments were conducted on public benchmark datasets and open-source implementations in isolated environments. No attacks targeted production systems. Findings were shared with affected project maintainers prior to publication.

Download Tool