Knowing When Not to Answer: Lightweight KB-Aligned OOD Detection for Safe RAG

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Triantafyllopoulos, Ilias, Qu, Renyi, Giorgi, Salvatore, Curtis, Brenda, Ungar, Lyle H., Sedoc, João
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866912830843781120
author Triantafyllopoulos, Ilias
Qu, Renyi
Giorgi, Salvatore
Curtis, Brenda
Ungar, Lyle H.
Sedoc, João
author_facet Triantafyllopoulos, Ilias
Qu, Renyi
Giorgi, Salvatore
Curtis, Brenda
Ungar, Lyle H.
Sedoc, João
contents Retrieval-Augmented Generation (RAG) systems are increasingly deployed in high-stakes domains, where safety depends not only on how a system answers, but also on whether a query should be answered given a knowledge base (KB). Out-of-domain (OOD) queries can cause dense retrieval to surface weakly related context and lead the generator to produce fluent but unjustified responses. We study lightweight, KB-aligned OOD detection as an always-on gate for RAG systems. Our approach applies PCA to KB embeddings and scores queries in a compact subspace selected either by explained-variance retention (EVR) or by a separability-driven t-test ranking. We evaluate geometric semantic-search rules and lightweight classifiers across 16 domains, including high-stakes COVID-19 and Substance Use KBs, and stress-test robustness using both LLM-generated attacks and an in-the-wild 4chan attack. We find that low-dimensional detectors achieve competitive OOD performance while being faster, cheaper, and more interpretable than prompted LLM-based judges. Finally, human and LLM-based evaluations show that OOD queries primarily degrade the relevance of RAG outputs, showing the need for efficient external OOD detection to maintain safe, in-scope behavior.
format Preprint
id arxiv_https___arxiv_org_abs_2508_02296
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Knowing When Not to Answer: Lightweight KB-Aligned OOD Detection for Safe RAG
Triantafyllopoulos, Ilias
Qu, Renyi
Giorgi, Salvatore
Curtis, Brenda
Ungar, Lyle H.
Sedoc, João
Computation and Language
Information Retrieval
Retrieval-Augmented Generation (RAG) systems are increasingly deployed in high-stakes domains, where safety depends not only on how a system answers, but also on whether a query should be answered given a knowledge base (KB). Out-of-domain (OOD) queries can cause dense retrieval to surface weakly related context and lead the generator to produce fluent but unjustified responses. We study lightweight, KB-aligned OOD detection as an always-on gate for RAG systems. Our approach applies PCA to KB embeddings and scores queries in a compact subspace selected either by explained-variance retention (EVR) or by a separability-driven t-test ranking. We evaluate geometric semantic-search rules and lightweight classifiers across 16 domains, including high-stakes COVID-19 and Substance Use KBs, and stress-test robustness using both LLM-generated attacks and an in-the-wild 4chan attack. We find that low-dimensional detectors achieve competitive OOD performance while being faster, cheaper, and more interpretable than prompted LLM-based judges. Finally, human and LLM-based evaluations show that OOD queries primarily degrade the relevance of RAG outputs, showing the need for efficient external OOD detection to maintain safe, in-scope behavior.
title Knowing When Not to Answer: Lightweight KB-Aligned OOD Detection for Safe RAG
topic Computation and Language
Information Retrieval
url https://arxiv.org/abs/2508.02296