A new study shows GraphRAG systems can be quietly sabotaged through the index they build to organize answers, not just the data they store.
Researchers describe an attack called Hop-Decayed Influence, or HDI, that targets a part of GraphRAG pipelines nobody was watching: the semantic summaries, hierarchical edges, and pre-computed relevance scores built during offline indexing. Instead of poisoning individual facts in a knowledge graph, HDI finds the few auxiliary structures with outsized influence on retrieval and corrupts those after indexing is done. Tested against Microsoft's GraphRAG and HippoRAG2 on two multi-hop question-answering benchmarks, the attack succeeded 88 to 94 percent of the time while altering as little as 0.016 percent of the auxiliary data. Because each tampered structure feeds multiple queries, a single edit can derail up to six separate answers, a multiplier effect the paper calls a Schema Leverage Ratio of 1:N.
That ratio is the real story. Earlier RAG attacks worked one node or edge at a time, which made them slow to scale and relatively easy to catch. HDI gets amplification for free by targeting the scaffolding retrieval systems lean on, and because that scaffolding is machine-generated text, it reads as normal system output, evading perplexity and paraphrase-based defenses more than 99 percent of the time.
If GraphRAG becomes the default way enterprises query their internal knowledge, this is a reminder that the index itself needs the same scrutiny as the documents going into it.