AI 中文总结
本文构建隐私保护向量搜索统一基准,在相同条件下对比SAP、EMVP等方案性能,明确各方案隐私与性能权衡关系,为从业者提供部署选择依据。
AI 中文摘要
向量搜索为语义搜索、推荐系统以及检索增强生成(RAG)提供核心支撑,按照设计,响应用户查询的服务会同时获取查询嵌入向量以及通常用于匹配的语料库,这对发起查询的用户和语料库所有者均构成隐私泄露问题。一类密码学方案(如SAP、EMVP、BNTM、Tip-toe)可解决该泄露问题,但由于各方案在自身语料库、威胁模型、参数选择、硬件及指标约定下发布和评估,相关性能数据无法直接比较,导致从业者在选择部署方案时缺乏合理依据。本文通过统一实验对比填补该空白,设置明文基线及四个密码学后端,在相同工作负载、硬件及指标定义下运行。结果显示,各方案在隐私性、性能、召回率方面呈现帕累托前沿分布,而非对性能造成统一损耗:SAP性能与明文基线相当;EMVP实现密码学不可区分性,但CPU吞吐量代价为明文的4倍;BNTM额外提供恶意服务器可验证性,中位数延迟代价进一步提升22倍;Tiptoe可隐藏集群选择本身,但单查询代价为明文的190倍;GPU加速对明文和SAP有效,但对EMVP和BNTM无效。所有实验产物公开可供复现。
英文摘要
Vector search powers semantic search, recommendation systems, and retrieval-augmented generation (RAG). By design, the service answering a query sees both the query embedding and, usually, the corpus against which it is matched. This is a privacy breach for both the user issuing the query and the owner of the corpus. A family of cryptographic schemes (e.g., SAP, EMVP, BNTM, Tip-toe) addresses that leak. However, as each scheme is published and evaluated on its own corpus, threat model, parameter choices, hardware, and metric conventions, the numbers cannot be compared directly. Consequently, a practitioner asking which one to deploy today has no defensible way to choose. We close that gap with a uniform experimental comparison, including a Plaintext baseline and four cryptographic backends running over the same workload, hardware, and metric definitions. Under that ruler, the schemes spread across a Pareto frontier in privacy, performance, and recall rather than imposing a flat penalty on performance. We find that the performance of SAP matches Plaintext, EMVP delivers cryptographic indistinguishability at a 4x throughput cost on CPU, BNTM adds malicious-server verifiability at a further 22x median-latency cost, and Tiptoe hides the cluster choice itself, but incurs a 190x per-query cost compared to Plaintext. GPU acceleration pays off for Plaintext and SAP but not for EMVP or BNTM. All our experiment artifacts are publicly available for reproducibility