acceptodds
Under review as a conference paper at ICLR 2027

One Record, Many Artifacts: Relational Metadata Leakage in GraphRAG

Abstract

GraphRAG transforms document collections into retrievable entities, relations, and summaries, enabling effective reasoning over relational evidence but also creating a new privacy surface: metadata that is weakly salient in source text can become directly addressable once materialized into graph-derived index artifacts. To study and mitigate this risk, we present a unified audit-and-repair framework for relational metadata leakage in GraphRAG. The framework combines relational canaries and matched controls for precisely traceable leakage auditing, retrieval-generation decomposition and representation analysis for identifying the mechanism of amplification, and ProvPatch, a provenance-aware repair method that traces confirmed targets through their source-to-index dependency closure and regenerates only affected artifacts. Across three multi-hop QA benchmarks, GraphRAG increases exact extraction by 28.7 percentage points over matched dense RAG. Our analyses show that this amplification arises primarily from relation-level materialization and increased retrieval exposure, rather than from a substantial change in conditional reproduction once the target has been retrieved. Under a five-turn adaptive attack, ProvPatch reduces exact extraction to zero and normalized identifier recovery to 0.002 while recomputing only 9.8-14.1% of the index. These results characterize relational materialization as a distinct source of metadata exposure in GraphRAG and show that provenance-guided local regeneration can repair this exposure without rebuilding the full index.

open until 14 Dec 2026

est. 32% chance this paper gets accepted at ICLR 2027.

Reject 68%Accept 32%

What do you think this paper will get?

All positions stay anonymous.

Related papers

Loading the map…

Discussion (0)

Sign in to comment.