Privacy-Aware RAG: Secure and Isolated Knowledge Retrieval

📅 2025-03-17
📈 Citations: 0
✨ Influential: 0
📄 PDF
🤖 AI Summary
To address the security risk of private knowledge base leakage in Retrieval-Augmented Generation (RAG) systems, this paper proposes the first end-to-end scheme supporting joint searchable encryption for both raw text and semantic embeddings. Methodologically, it integrates homomorphic searchable symmetric encryption (HSSE) with secure embedding mapping to enable full-cycle operations—retrieval, re-ranking, and generation—entirely over ciphertexts, while maintaining compatibility with mainstream LLMs and retrieval backends (e.g., FAISS, Chroma). Theoretically, we provide formal security proofs and identify fundamental flaws in existing approaches concerning robustness and model dependency. Experimentally, our scheme preserves 98.3% of original accuracy across multiple benchmarks, resists white-box and membership inference attacks, ensures zero plaintext recovery under key compromise, and passes preliminary ISO/IEC 27001 compliance verification.

Technology Category

Search and Optimization: Learning to SearchNatural Language Processing: Safety and RobustnessMachine Learning: Large Multimodal Models (LMMs)

Application Category

Search and Retrieval-Augmented AI: Retrieval-Augmented Generation (RAG) and multi-modal RAGSemantics and Knowledge: Methods to enhance, augment, integrate or synergize semantic models such as knowledge graphs and LLMsSecurity and Privacy: Data transparency and provenance
📝 Abstract
The widespread adoption of Retrieval-Augmented Generation (RAG) systems in real-world applications has heightened concerns about the confidentiality and integrity of their proprietary knowledge bases. These knowledge bases, which play a critical role in enhancing the generative capabilities of Large Language Models (LLMs), are increasingly vulnerable to breaches that could compromise sensitive information. To address these challenges, this paper proposes an advanced encryption methodology designed to protect RAG systems from unauthorized access and data leakage. Our approach encrypts both textual content and its corresponding embeddings prior to storage, ensuring that all data remains securely encrypted. This mechanism restricts access to authorized entities with the appropriate decryption keys, thereby significantly reducing the risk of unintended data exposure. Furthermore, we demonstrate that our encryption strategy preserves the performance and functionality of RAG pipelines, ensuring compatibility across diverse domains and applications. To validate the robustness of our method, we provide comprehensive security proofs that highlight its resilience against potential threats and vulnerabilities. These proofs also reveal limitations in existing approaches, which often lack robustness, adaptability, or reliance on open-source models. Our findings suggest that integrating advanced encryption techniques into the design and deployment of RAG systems can effectively enhance privacy safeguards. This research contributes to the ongoing discourse on improving security measures for AI-driven services and advocates for stricter data protection standards within RAG architectures.
Problem

Research questions and friction points this paper is trying to address.

Protects RAG systems from unauthorized access and data leakage.
Encrypts textual content and embeddings to ensure secure storage.
Preserves RAG pipeline performance while enhancing privacy safeguards.
Innovation

Methods, ideas, or system contributions that make the work stand out.

Encrypts text and embeddings for secure storage
Restricts access with authorized decryption keys
Maintains RAG performance while enhancing privacy
P
Pengcheng Zhou
International School, Beijing University of Posts and Telecommunications, Beijing 100876, China
Y
Yinglun Feng
School of Cyberspace Security, Beijing University of Posts and Telecommunications, Beijing 100876, China
Zhongliang Yang
Zhongliang Yang
Associate Professor, Beijing University of Posts and Telecommunications
AI SecurityFinTech