arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

检索增强生成中的外部数据库保护是静态的吗?重新思考动态查询下的隐私保护

Is External Database Protection Static in Retrieval-Augmented Generation? Rethinking Privacy Preservation under Dynamic Queries

Gang Zhang, Mingyu Tian, Xukun Luan, Yuanchi Ma, Jinyan Liu

arXiv 2607.14811首次发表:更新:

AI 中文总结

研究检索增强生成中外部数据库隐私保护问题,提出Prompt-Aware动态分层差分隐私框架PA-HDP,通过风险分层评估和自适应保护,在减少隐私泄露的同时保持高检索质量,实现更好的隐私-效用权衡。

AI 中文摘要

检索增强生成(RAG)通过外部文档检索增强大语言模型,但检索到的上下文可能会泄露敏感信息。当前隐私保护方法通常依赖文档级静态风险假设,忽略了RAG中文档隐私风险高度依赖用户查询这一特性。为此提出Prompt-Aware动态分层差分隐私框架(PA-HDP),先进行风险分层动态评估风险,再应用自适应敏感实体替换和基于指数机制的文本选择提供差异化隐私保护。实验表明PA-HDP能显著减少隐私泄露并保持高检索质量。

英文摘要

Retrieval-augmented generation (RAG) enhances large language models via external document retrieval, but retrieved contexts may leak sensitive information. Current privacy protection methods typically rely on a document-level static risk assumption, treating all retrieved documents as having the same privacy leakage risk. However, this assumption overlooks a fundamental characteristic of RAG: the privacy risk of a document is highly dependent on the user's query, making privacy leakage inherently query-driven and dynamic. To address this challenge, we propose a Prompt-Aware Dynamic Hierarchical Differential Privacy framework (PA-HDP) for privacy-preserving RAG. PA-HDP first performs a prompt-aware risk hierarchy to dynamically assess privacy risks under different queries. It then applies adaptive sensitive entity replacement and exponential mechanism-based text selection to provide differentiated privacy protection while preserving semantic utility. By protecting only the content that is truly sensitive under a given query, PA-HDP minimizes unnecessary modifications to the retrieval corpus. Extensive experiments on benchmark datasets demonstrate that PA-HDP significantly reduces privacy leakage while maintaining high retrieval quality, achieving a better privacy-utility trade-off than prior methods.

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑