arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

GoldenRetriever:用于隐私保护RAG的非交互式同态加密检索

GoldenRetriever: Non-Interactive Homomorphic Encrypted Retrieval for Privacy-Preserving RAG

Yang Gao, Gang Quan, Scott Piersall, Qian Lou, Dongdong Wang, Liqiang Wang

arXiv 2607.29019首次发表:更新:

发表机构

University of Central Florida; Florida International University; University of Florida(中佛罗里达大学; 佛罗里达国际大学; 佛罗里达大学)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

针对现有隐私保护RAG检索方案延迟高、易泄露的问题,提出基于阈值选择的非交互式同态加密检索框架,通过CKKS同态计算与掩码极化方法实现高效安全的检索,性能优于排名式加密方法。

AI 中文摘要

检索增强生成(RAG)通过整合外部知识提升大语言模型性能,但现有流程通常在明文数据上运行,引发严重隐私问题。此前隐私保护检索的研究利用同态加密(HE)、私有信息检索(PIR)等密码技术,但常依赖交互式协议或基于排名的选择机制,导致高延迟与潜在信息泄露。本文提出一种基于阈值选择的实用非交互式加密检索框架,用于RAG。该方法不执行加密下昂贵的Top-k排名,而是选择相似度得分超过预定义阈值的文档,将计算复杂度从语料库规模的二次方降至线性。我们采用基于CKKS的同态计算实现该设计,支持全加密相似度评估与文档选择,不会泄露查询内容、中间得分或所选索引。为弥合近似加密计算与离散令牌重构的差距,我们引入精度稳定的掩码极化方法,确保所选文档的准确恢复。在标准检索基准上的实验表明,我们的方法实现了有竞争力的检索有效性,同时与基于排名的加密方法相比显著降低了延迟。这些结果凸显基于阈值的选择是可扩展且安全的RAG系统的实用基础。

英文摘要

Retrieval-Augmented Generation (RAG) enhances large language models by incorporating external knowledge, but existing pipelines typically operate on plaintext data, raising significant privacy concerns. Prior work on privacy-preserving retrieval leverages cryptographic techniques such as homomorphic encryption (HE) and private information retrieval (PIR), but often relies on interactive protocols or ranking-based selection mechanisms that incur high latency and potential information leakage. In this paper, we propose a practical non-interactive encrypted retrieval framework for RAG based on threshold selection. Instead of performing expensive top-$k$ ranking under encryption, our approach selects documents whose similarity scores exceed a predefined threshold, reducing computational complexity from quadratic to linear in the corpus size. We implement this design using CKKS-based homomorphic computation, enabling fully encrypted similarity evaluation and document selection without revealing query content, intermediate scores, or selected indices. To bridge the gap between approximate encrypted computation and discrete token reconstruction, we introduce a precision-stable mask polarization method that ensures accurate recovery of selected documents. Experiments on standard retrieval benchmarks demonstrate that our approach achieves competitive retrieval effectiveness while significantly reducing latency compared to ranking-based encrypted methods. These results highlight threshold-based selection as a practical foundation for scalable and secure RAG systems.

Comments10 pages

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑