arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

通过向外部大语言模型隐藏敏感信息实现隐私保护的检索增强生成(RAG)

Privacy-Preserving RAG by Concealing Sensitive Information from External LLMs

Saleh Almohaimeed, Saad Almohaimeed, Mousa Jari, Fahad Alotaibi, Khalid A. Alobaid, Mohamad Mahmoud Al Rahhal

arXiv 2608.12675首次发表:更新:

发表机构

College of Applied Computer Science, King Saud University; Institution of Public Administration(沙特国王大学应用计算机科学学院; 公共行政学院)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

本文提出SEAG隐私保护框架,通过构建实体替换表替换敏感信息,在向外部LLM隐藏敏感数据的同时保障RAG的回答准确性,相关模型在多维度评估中表现良好。

AI 中文摘要

检索增强生成(RAG)被广泛用于提升大语言模型(LLMs)在回答用户查询时的性能。现有针对RAG的隐私研究主要聚焦于防止未授权用户访问敏感数据,但RAG隐私研究中常被忽视的另一重要问题是:外部生成器可访问查询内容和检索到的文档,这些内容可能包含机密信息,存在被滥用或用于非预期用途的风险。本文提出敏感实体别名生成器(SEAG)这一隐私保护框架,使用户可借助强大的第三方生成器而无需披露敏感信息。SEAG引入轻量级模型,用于定位敏感实体、生成对应别名并构建实体替换表;该表用于在将用户查询和检索到的文档转发给外部生成器前,替换其中的敏感词汇。为此,本文构建了两个数据集:一个用于微调SEAG模型以生成实体替换表,另一个用于评估整个SEAG框架。实验结果表明SEAG框架表现良好:用于衡量模型在向外部生成器隐藏敏感信息的同时为用户提供正确响应能力的用户指标,所有SEAG模型均达到80%以上的准确率;额外分析评估了SEAG模型Qwen-3、LLaMA-3.2和Phi-4在给定文档中隐藏所有敏感实体的能力,总准确率分别为77.83%、76.73%和74.91%,表现优异。

英文摘要

Retrieval-Augmented Generation (RAG) is widely used to improve the performance of Large Language Models (LLMs) in answering user queries. Existing privacy research on RAG has focused on preventing unauthorized users from accessing sensitive data. However, another important problem that is often overlooked in RAG privacy research is that external generators have access to the query and the retrieved documents, which may contain confidential information that could potentially be misused or accessed for unintended purposes. In this paper, we introduce the Sensitive Entity Alias Generator (SEAG), a privacy-preserving framework that empowers users to utilize powerful third-party generators without disclosing sensitive information. SEAG introduces a lightweight model that locates sensitive entities, generates corresponding aliases, and constructs an entity replacement table. The table is used to replace sensitive words in the user's query and in the retrieved documents before they are forwarded to an external generator. For this purpose, two datasets were constructed: one for fine-tuning SEAG models to generate entity replacement tables, and another for evaluating the entire SEAG framework. The experimental results demonstrate the success of the SEAG framework. As for the User metric, which measures the ability of the model to provide a correct response to the user while hiding sensitive information from the external generator, all SEAG models achieved over 80% accuracy. Additional analysis further evaluated the ability of SEAG models Qwen-3, LLaMA-3.2, and Phi-4 to hide all sensitive entities within given documents. The results show good performance with total accuracies of 77.83%, 76.73%, and 74.91%, respectively.

CommentsSubmitted

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑