arXiv AI

Hop-Decayed Influence: New Vulnerabilities of Structural Auxiliary Indexing in GraphRAG Pipelines with LLM

The paper introduces the Hop-Decayed Influence (HDI) attack, which targets auxiliary schema-level structures—semantic summaries, hierarchical edges, and pre-computed scores—used in GraphRAG pipelines for retrieval prioritisation. By propagating query-aware influence, HDI identifies high-impact targets and corrupts a minuscule fraction (as low as 0.016%) of these structures, achieving an 88–94% success rate across HotpotQA and 2WikiMultiHopQA benchmarks on Microsoft GraphRAG and HippoRAG2 architectures. The modifications affect up to six queries each, yielding a 1:N amplification that instance-level attacks cannot achieve, and they evade perplexity and paraphrase defenses with over 99% evasion, exposing a structural blind spot in current GraphRAG defenses.

arXiv AI
Jul 7

SoK: Systematizing LLM Prompt Security: Taxonomies, Datasets, and Unified Evaluation of Attacks and Defenses

arXiv:2510. 15476v3 Announce Type: replace-cross Abstract: Large Language Models (LLMs) are increasingly used as interfaces to information, code, and real-world services, making prompt-level security failures a practical concern.

By Hanbin Hong, Shuang Wu, Shuya Feng, Nima Naderloui, Shenao Yan, Jingyu Zhang, Ali Arastehfard, Heqing Huang, Yuan Hong
arXiv Computation and Language
Aug 31

A Wolf in Sheep's Clothing: Targeted Routing Hijacking in Federated RAG

The paper exposes a new vulnerability in Federated Retrieval-Augmented Generation (FedRAG) called Routing Hijacking, where a malicious client forges its semantic profile to attract target queries despite lacking relevant data. Experiments across three FedRAG routing architectures show that this attack consistently misroutes queries, causing downstream failures such as missing evidence, poisoning, incorrect answers, hallucinations, and sycophantic behavior. The authors propose a trust‑aware post‑routing framework that reweights clients based on evidence feedback, which effectively suppresses persistent hijacking and transfers to a learned neural router.

By Junjie Mu, Qiongxiu Li