Query-Efficient Agentic Graph Extraction Attacks on GraphRAG Systems

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Yang, Shuhua, Zhang, Jiahao, Wang, Yilong, Lee, Dongwon, Wang, Suhang
Format: Preprint
Published: 2026
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866914490656751616
author Yang, Shuhua
Zhang, Jiahao
Wang, Yilong
Lee, Dongwon
Wang, Suhang
author_facet Yang, Shuhua
Zhang, Jiahao
Wang, Yilong
Lee, Dongwon
Wang, Suhang
contents Graph-based retrieval-augmented generation (GraphRAG) systems construct knowledge graphs over document collections to support multi-hop reasoning. While prior work shows that GraphRAG responses may leak retrieved subgraphs, the feasibility of query-efficient reconstruction of the hidden graph structure remains unexplored under realistic query budgets. We study a budget-constrained black-box setting where an adversary adaptively queries the system to steal its latent entity-relation graph. We propose AGEA (Agentic Graph Extraction Attack), a framework that leverages a novelty-guided exploration-exploitation strategy, external graph memory modules, and a two-stage graph extraction pipeline combining lightweight discovery with LLM-based filtering. We evaluate AGEA on medical, agriculture, and literary datasets across Microsoft-GraphRAG and LightRAG systems. Under identical query budgets, AGEA significantly outperforms prior attack baselines, recovering up to 90% of entities and relationships while maintaining high precision. These results demonstrate that modern GraphRAG systems are highly vulnerable to structured, agentic extraction attacks, even under strict query limits. The code is available at https://github.com/shuashua0608/AGEA.
format Preprint
id arxiv_https___arxiv_org_abs_2601_14662
institution arXiv
publishDate 2026
record_format arxiv
spellingShingle Query-Efficient Agentic Graph Extraction Attacks on GraphRAG Systems
Yang, Shuhua
Zhang, Jiahao
Wang, Yilong
Lee, Dongwon
Wang, Suhang
Artificial Intelligence
Multiagent Systems
Graph-based retrieval-augmented generation (GraphRAG) systems construct knowledge graphs over document collections to support multi-hop reasoning. While prior work shows that GraphRAG responses may leak retrieved subgraphs, the feasibility of query-efficient reconstruction of the hidden graph structure remains unexplored under realistic query budgets. We study a budget-constrained black-box setting where an adversary adaptively queries the system to steal its latent entity-relation graph. We propose AGEA (Agentic Graph Extraction Attack), a framework that leverages a novelty-guided exploration-exploitation strategy, external graph memory modules, and a two-stage graph extraction pipeline combining lightweight discovery with LLM-based filtering. We evaluate AGEA on medical, agriculture, and literary datasets across Microsoft-GraphRAG and LightRAG systems. Under identical query budgets, AGEA significantly outperforms prior attack baselines, recovering up to 90% of entities and relationships while maintaining high precision. These results demonstrate that modern GraphRAG systems are highly vulnerable to structured, agentic extraction attacks, even under strict query limits. The code is available at https://github.com/shuashua0608/AGEA.
title Query-Efficient Agentic Graph Extraction Attacks on GraphRAG Systems
topic Artificial Intelligence
Multiagent Systems
url https://arxiv.org/abs/2601.14662