发表机构
Georgia Institute of Technology(佐治亚理工学院)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
针对联邦RAG中拜占庭节点攻击,利用诚实节点跨步骤一致性,通过对齐校准与固定成员共形预测,在有限样本下提供覆盖保证,并实现更小的预测集。
AI 中文摘要
检索增强生成(RAG)通过查阅相关文档,使语言模型能够更准确地回答问题。许多有价值的文档集合,如医疗记录,因隐私规则而无法集中存储。联邦RAG将每个集合保留在其所有者(即节点)处,各节点根据自身文档对候选答案进行评分;中央枢纽汇总这些评分。部分节点(称为拜占庭节点)可能被攻破、发生故障或受文档中隐藏指令误导,从而报告任意评分。共形预测通过在校准步骤中针对已知答案的问题设定截断值,返回一个以选定概率包含正确答案的集合。一个未知的节点组(其规模不超过声明的上界)可能在校准步骤和查询时均进行错误报告。现有方法假设所有节点诚实,或仅保护校准步骤。我们观察到,诚实节点在两个步骤中是相同的。因此,枢纽让所有节点对相同的校准问题进行评分,并且仅当某个合理的诚实节点组(在两个步骤中均使用其自身评分)会保留某个候选答案时,枢纽才保留该候选答案。我们证明,无论拜占庭节点报告什么,所得集合在有限样本中以选定概率包含正确答案。任何使用相同信息的方法若返回更小的集合,则可能丢失诚实节点支持的答案。若节点随机失效,则保证仅因失效节点数超过声明的概率而减弱。在模拟中,针对真实问答任务(包括医学考试),并以语言模型作为节点(部分被劫持),只要行为异常的节点数不超过声明值,我们的集合即可达到目标,而简单平均可能无法达到。与具有相同保护的更简单方法相比,我们的集合明显更小,尤其在声明上界宽松时最为显著,因此谨慎的上界代价很小。
英文摘要
Retrieval-augmented generation (RAG) lets language models answer questions more accurately by consulting relevant documents. Many valuable collections, such as medical records, cannot be pooled because of privacy rules. Federated RAG leaves each collection with its owner, or node, which scores candidate answers from its own documents; a central hub combines the scores. Some nodes, called Byzantine, may be compromised, faulty, or misled by instructions hidden in documents, and report arbitrary scores. Conformal prediction returns a set containing the correct answer with a chosen probability, using a cutoff set in a calibration step on questions with known answers. An unknown group of nodes, no larger than a declared bound, may misreport both in this step and at query time. Existing methods assume every node is honest or protect only the calibration step. We observe that the honest nodes are the same in both steps. The hub therefore has all nodes score the same calibration questions, and keeps a candidate only if some plausible group of honest nodes, using its own scores in both steps, would keep it. We prove that the resulting sets contain the correct answer with the chosen probability in finite samples, whatever the Byzantine nodes report. No method using the same information can return smaller sets without risking the loss of an answer the honest nodes support. If nodes fail at random, the guarantee weakens only by the probability that more nodes fail than declared. In simulations, on real question-answering tasks including medical exams, and with language models as nodes, some hijacked, our sets reached the target whenever no more nodes misbehaved than declared, while plain averaging could miss it. They were also clearly smaller than those of simpler methods with the same protection, most of all when the declared bound was generous, so a cautious bound costs little.