
Research implementation of Hop-Decayed Influence (HDI) and the 3S attack framework, exposing structural auxiliary indexing vulnerabilities in GraphRAG pipelines with LLMs.
Jisung Park, John Le, Heath Cooper
Institute of Cybersecurity and Cryptology (iC²), University of Wollongong
IFIP SEC 2026
jspacific0307/HDI-graphragpipeline https://huggingface.co/datasets/jspacific0307/HDI-graphragpipeline
GraphRAG pipelines construct auxiliary structures during offline indexing — semantic summaries, hierarchical edges, and pre-computed scores — that existing attacks completely overlook.
This paper formalises Auxiliary Schema-Level Entity as a novel attack surface and proposes:
| Metric | Value |
|---|---|
| Attack Success Rate (ASR) | 88%+ across all configurations |
| Modification Ratio | as low as 0.016% of total structures |
| Schema Leverage Ratio (SLR) | up to 6.00 (queries affected per modification) |
| Perplexity Filter Evasion | 99.5%+ |
| Paraphrase Defense Evasion | 99.1%+ |
Query → Entity Extraction → KG Mapping → HDI Target Selection → 3S Attack
| Attack | Target | Method |
|---|---|---|
| Semantic (S) | Textual summaries | Inject adversarial text with low perplexity |
| Structure (T) | Hierarchical edges | Add misleading edges to semantically distant nodes |
| Score (C) | Pre-computed scores | Demote high-ranked nodes, promote irrelevant ones |
Influence propagates from seed entities with exponential decay by hop distance:
$$\text{Influence}(v) = \sum_{q \in Q} \sum_{s \in \text{Seeds}(q)} \lambda^{d(s,v)}$$
Baselines
Datasets
Models
text-embedding-3-small (OpenAI)GPT-4o-mini (OpenAI)| System | Dataset | Best Config | ASR (%) | Mod. Ratio (%) | SLR |
|---|---|---|---|---|---|
| MS GraphRAG | HotpotQA | HDI-T | 91.69 | 4.74 | 4.57 |
| MS GraphRAG | 2WikiMHQA | HDI-T | 88.17 | 4.82 | 3.41 |
| HippoRAG2 | HotpotQA | HDI-T | 88.24 | 0.075 | 5.80 |
| HippoRAG2 | 2WikiMHQA | HDI-C | 94.44 | 0.016 | 6.00 |
git clone https://github.com/Jisung-Pacific/HDI-GraphRAG-Attack
cd HDI-GraphRAG-Attack
pip install -r requirements.txt
@inproceedings{park2026hdi,
title = {Hop-Decayed Influence: New Vulnerabilities of Structural Auxiliary Indexing in GraphRAG Pipelines with LLM},
author = {Park, Jisung and Le, John and Cooper, Heath},
booktitle = {IFIP International Information Security and Privacy Conference (SEC)},
year = {2026}
}
All experiments were conducted on public benchmark datasets and open-source implementations in isolated environments. No attacks targeted production systems. Findings were shared with affected project maintainers prior to publication.