Skip to content

Is External Database Protection Static in Retrieval-Augmented Generation? Rethinking Privacy Preservation under Dynamic Queries

Jul 2026 · arXiv.org · Vol abs/2607.14811 · 0 citations · 41 references
Computer Science

TL;DR

A Prompt-Aware Dynamic Hierarchical Differential Privacy framework (PA-HDP) is proposed, which performs a prompt-aware risk hierarchy to dynamically assess privacy risks under different queries and applies adaptive sensitive entity replacement and exponential mechanism-based text selection to provide differentiated privacy protection while preserving semantic utility.

Abstract

Retrieval-augmented generation (RAG) enhances large language models via external document retrieval, but retrieved contexts may leak sensitive information. Current privacy protection methods typically rely on a document-level static risk assumption, treating all retrieved documents as having the same privacy leakage risk. However, this assumption overlooks a fundamental characteristic of RAG: the privacy risk of a document is highly dependent on the user's query, making privacy leakage inherently query-driven and dynamic. To address this challenge, we propose a Prompt-Aware Dynamic Hierarchical Differential Privacy framework (PA-HDP) for privacy-preserving RAG. PA-HDP first performs a prompt-aware risk hierarchy to dynamically assess privacy risks under different queries. It then applies adaptive sensitive entity replacement and exponential mechanism-based text selection to provide differentiated privacy protection while preserving semantic utility. By protecting only the content that is truly sensitive under a given query, PA-HDP minimizes unnecessary modifications to the retrieval corpus. Extensive experiments on benchmark datasets demonstrate that PA-HDP significantly reduces privacy leakage while maintaining high retrieval quality, achieving a better privacy-utility trade-off than prior methods.

View source

Similar papers

Preprint Aug 2026

Privacy-Preserving RAG by Concealing Sensitive Information from External LLMs

This paper introduces the Sensitive Entity Alias Generator (SEAG), a privacy-preserving framework that empowers users to utilize powerful third-party generators without disclosing sensitive information and demonstrates the success of the SEAG framework.

Saleh Almohaimeed, Saad Almohaimeed, Mousa Jari et al. · 0 citations
Open access Jul 2026

Privacy-Aware Adaptive Differential Privacy for Semantic Retrieval: A Pii-Aware Dynamic Budget Allocation Framework

PADP is presented, a sensitivity-aware perturbation framework inspired by differential privacy principles, which provides a plug-and-play, middleware framework that can be easily integrated into enterprise RAG pipelines without requiring costly computations for LLM fine-tuning and reconstruction of vector indices.

Seçkin Mandaci, Yılmaz Vural, Ö. Turna · 0 citations
Review Open access Aug 2026

Security and privacy challenges of RAG systems

This study presents a detailed, actionable approach to constructing secure, privacy-focused RAG systems and culminates in the Integrated Privacy-Preserving RAG Framework (IPRAG), a five-tier architecture supported by a three-phase deployment protocol.

Firoz Mohammed Ozman · 0 citations
Book Open access Jul 2026

Privacy Preserving Information Retrieval: Defining Privacy Research Pillars for a Future Research Agenda

Advancements in computer science are raising concerns and preoccupations about the privacy of users' data submitted to and used by Information Retrieval (IR) systems. IR systems, such as search engines, integrate new generative information access pipelines that implement effective and efficient document retrieval and answer generation. However, critical challenges arise in Privacy-Preserving IR (PPIR): Are such data leaking personal information or being used to train generative systems? Are current privacy solutions sufficient to guarantee user privacy and limit such information leakage? Are users' queries and retrieved documents protected throughout the entire retrieval process? How has the privacy threats landscape changed, and in which directions should the IR and Privacy research community investigate to address such new risks? In this perspective paper, we provide initial answers to these questions, analysing state-of-the-art solutions for protecting user privacy when accessing information and highlighting areas of concern. We propose a new PPIR research agenda to address the unsolved problem of private data use and access. The agenda includes novel privacy research pillars aimed at addressing objectives grounded in gaps in the literature, user survey findings, and structured interviews with experts from research, industry, and regulatory bodies. By defining these privacy research pillars, we advise the IR community to pursue research toward a more resilient privacy direction that can address future challenges stemming from rapidly advancing technology eager for user data.

Francesco Luigi De Faveri, G. Faggioli, Asia J. Biega et al. · 0 citations
#small language model Open access Aug 2026

GS-Chaff: Multi-Agent Prompt-Level Semantic Chaffing for Privacy-Preserving LLM Inference

Generative semantic chaffing (GS-Chaff), a training-free multi-agent framework for privacy-preserving LLM inference over natural-language text queries that hides the user’s true intent among semantically plausible chaff queries, is proposed.

Quan Zhou, Zhi-Cheng Wang, Zhengjun Yue et al. · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.