Skip to content
Review Open access

Security and privacy challenges of RAG systems

Aug 2026 · International Journal of Frontiers in Science and Technology Research · 0 citations

TL;DR

This study presents a detailed, actionable approach to constructing secure, privacy-focused RAG systems and culminates in the Integrated Privacy-Preserving RAG Framework (IPRAG), a five-tier architecture supported by a three-phase deployment protocol.

Abstract

Retrieval-Augmented Generation (RAG) systems enable robust knowledge integration for large language models but also pose significant security and privacy risks. RAG systems combine two components: a retriever, which searches external data sources for relevant information, and a generator, typically a large language model that uses both the retrieved documents and user queries to produce answers. This study conducts a systematic literature review to assess these challenges using Socio-Technical Systems Theory (which considers interactions among people, technology, and organizational context) and Privacy by Design (PbD, a framework for embedding privacy into system design). Addressing five objectives, the research detects and classifies privacy attacks, evaluates risks throughout the storage, retrieval, and generation phases, scrutinizes measurement methods, contrasts mitigation strategies, and introduces a unified solution. The work culminates in the Integrated Privacy-Preserving RAG Framework (IPRAG), a five-tier architecture supported by a three-phase deployment protocol. This study presents a detailed, actionable approach to constructing secure, privacy-focused RAG systems.

Read PDF

Similar papers

Preprint Aug 2026

Privacy-Preserving RAG by Concealing Sensitive Information from External LLMs

This paper introduces the Sensitive Entity Alias Generator (SEAG), a privacy-preserving framework that empowers users to utilize powerful third-party generators without disclosing sensitive information and demonstrates the success of the SEAG framework.

Saleh Almohaimeed, Saad Almohaimeed, Mousa Jari et al. · 0 citations
Preprint Aug 2026

RH-RAG: Trustworthy Long-Form Generation for Privacy-Constrained Settings

Evaluations across literary, financial, and legal domains demonstrate that RH-RAG consistently improves factual grounding, semantic coherence, and document-level alignment compared to standard and hierarchical RAG baselines, while achieving reliability competitive with proprietary cloud-based systems without compromising data privacy.

Rajbhan Singh · 0 citations
Jul 2026

Is External Database Protection Static in Retrieval-Augmented Generation? Rethinking Privacy Preservation under Dynamic Queries

A Prompt-Aware Dynamic Hierarchical Differential Privacy framework (PA-HDP) is proposed, which performs a prompt-aware risk hierarchy to dynamically assess privacy risks under different queries and applies adaptive sensitive entity replacement and exponential mechanism-based text selection to provide differentiated privacy protection while preserving semantic utility.

Gang Zhang, Mingyu Tian, Xu-Kun Luan et al. · 0 citations
Book Open access Jul 2026

Privacy Preserving Information Retrieval: Defining Privacy Research Pillars for a Future Research Agenda

Advancements in computer science are raising concerns and preoccupations about the privacy of users' data submitted to and used by Information Retrieval (IR) systems. IR systems, such as search engines, integrate new generative information access pipelines that implement effective and efficient document retrieval and answer generation. However, critical challenges arise in Privacy-Preserving IR (PPIR): Are such data leaking personal information or being used to train generative systems? Are current privacy solutions sufficient to guarantee user privacy and limit such information leakage? Are users' queries and retrieved documents protected throughout the entire retrieval process? How has the privacy threats landscape changed, and in which directions should the IR and Privacy research community investigate to address such new risks? In this perspective paper, we provide initial answers to these questions, analysing state-of-the-art solutions for protecting user privacy when accessing information and highlighting areas of concern. We propose a new PPIR research agenda to address the unsolved problem of private data use and access. The agenda includes novel privacy research pillars aimed at addressing objectives grounded in gaps in the literature, user survey findings, and structured interviews with experts from research, industry, and regulatory bodies. By defining these privacy research pillars, we advise the IR community to pursue research toward a more resilient privacy direction that can address future challenges stemming from rapidly advancing technology eager for user data.

Francesco Luigi De Faveri, G. Faggioli, Asia J. Biega et al. · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.