arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

指明路径,隐藏目的地:大规模实用私有密集检索

Pointing the Way, Hiding the Destination: Practical Private Dense Retrieval at Scale

Peichun Hua, Danyang Chen, Junan Zhang, Haifeng Sun, Jingyu Wang, Diwen Xue, Mingyu Li, Yunming Xiao

arXiv 2608.25735首次发表:更新:

发表机构

The Chinese University of Hong Kong, Shenzhen; Tsinghua University; Beijing University of Posts and Telecommunications; The Chinese University of Hong Kong; Institute of Software, Chinese Academy of Sciences(香港中文大学(深圳); 清华大学; 北京邮电大学; 香港中文大学; 中国科学院软件研究所)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

该研究针对私有密集检索的成本与质量平衡问题,将深度哈希用作私有过滤器,结合加密重排序等技术,在保证检索准确性的同时降低了延迟,满足差分隐私要求,实现了大规模实用的私有密集检索。

AI 中文摘要

托管检索增强生成(RAG)和语义搜索允许用户查询提供商持有的有价值语料库,这引发了两个相互竞争的需求:隐藏每个查询和所选结果,同时仅披露用户被授权接收的文档。现有的密码学方法要么因每次查询处理整个语料库而成本高昂,要么因扫描少量集群而在效率上牺牲质量。我们将学习到的深度哈希重新用作私有过滤器:随机二进制代码为提供商指向一个短候选列表,而加密重排序和不经意密钥传输则保护精确查询和最终选择。该候选列表绕过了全语料库密码学搜索,同时不牺牲检索质量:在跨越25000到540万份文档的五个零样本语料库上,使用200-500个候选时,其检索效果与全语料库检索非常接近。在10 Gbps链路上的完整268万段落NQ语料库上,我们的协议仅在128-token Qwen3-32B RAG流水线的基础上增加了0.73秒,即10%的延迟。发布的代码满足定向度量差分隐私(DP),并大幅减少了嵌入反转和属性推断泄露,表明精心学习的候选列表可使私有密集检索同时兼具准确性和实用性。

英文摘要

Hosted retrieval-augmented generation (RAG) and semantic search allow users to query valuable provider-held corpora, raising two competing demands: to hide each query and chosen result, yet reveal only the documents that the user is authorized to receive. Existing cryptographic approaches either make this costly by processing the entire corpus for every query, or sacrifice quality for efficiency by scanning a few clusters. We repurpose learned deep hashing as a private filter: a randomized binary code points the provider to a short candidate list, while encrypted reranking and oblivious key transfer protect the precise query and final selection. This shortlist short-circuits full-corpus cryptographic search without sacrificing retrieval quality: with 200-500 candidates, it closely matches full-corpus retrieval across five zero-shot corpora spanning 25K to 5.4M documents. On the full 2.68M-passage NQ corpus over a 10-Gbps link, our protocol only adds 0.73 seconds, or 10 percent, to a 128-token Qwen3-32B RAG pipeline. The released code satisfies directional metric differential privacy (DP) and substantially reduces embedding-inversion and property-inference leakage, demonstrating that a carefully learned shortlist can make private dense retrieval both accurate and practical.

Comments31 pages, 9 figures, 16 tables

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑