Differentially Private Synthetic Text Generation for Retrieval-Augmented Generation (RAG)

Fuente: arXiv
Guardado en:
Detalles Bibliográficos
Autores principales: Mori, Junki, Kakizaki, Kazuya, Miyagawa, Taiki, Sakuma, Jun
Formato: Preprint
Publicado: 2025
Materias:
Acceso en línea:
Etiquetas: Agregar Etiqueta
Sin Etiquetas, Sea el primero en etiquetar este registro!
_version_ 1866914558804754432
author Mori, Junki
Kakizaki, Kazuya
Miyagawa, Taiki
Sakuma, Jun
author_facet Mori, Junki
Kakizaki, Kazuya
Miyagawa, Taiki
Sakuma, Jun
contents Retrieval-Augmented Generation (RAG) enhances large language models (LLMs) by grounding them in external knowledge. However, its application in sensitive domains is limited by privacy risks. Existing private RAG methods typically rely on query-time differential privacy (DP), which requires repeated noise injection and leads to accumulated privacy loss. To address this issue, we propose DP-SynRAG, a framework that uses LLMs to generate differentially private synthetic RAG databases. Unlike prior methods, the synthetic text can be reused once created, thereby avoiding repeated noise injection and additional privacy costs. To preserve essential information for downstream RAG tasks, DP-SynRAG extends private prediction, which instructs LLMs to generate text that mimics subsampled database records in a DP manner. Experiments show that DP-SynRAG achieves superior performance to the state-of-the-art private RAG systems while maintaining a fixed privacy budget, offering a scalable solution for privacy-preserving RAG.
format Preprint
id arxiv_https___arxiv_org_abs_2510_06719
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Differentially Private Synthetic Text Generation for Retrieval-Augmented Generation (RAG)
Mori, Junki
Kakizaki, Kazuya
Miyagawa, Taiki
Sakuma, Jun
Cryptography and Security
Computation and Language
Machine Learning
Retrieval-Augmented Generation (RAG) enhances large language models (LLMs) by grounding them in external knowledge. However, its application in sensitive domains is limited by privacy risks. Existing private RAG methods typically rely on query-time differential privacy (DP), which requires repeated noise injection and leads to accumulated privacy loss. To address this issue, we propose DP-SynRAG, a framework that uses LLMs to generate differentially private synthetic RAG databases. Unlike prior methods, the synthetic text can be reused once created, thereby avoiding repeated noise injection and additional privacy costs. To preserve essential information for downstream RAG tasks, DP-SynRAG extends private prediction, which instructs LLMs to generate text that mimics subsampled database records in a DP manner. Experiments show that DP-SynRAG achieves superior performance to the state-of-the-art private RAG systems while maintaining a fixed privacy budget, offering a scalable solution for privacy-preserving RAG.
title Differentially Private Synthetic Text Generation for Retrieval-Augmented Generation (RAG)
topic Cryptography and Security
Computation and Language
Machine Learning
url https://arxiv.org/abs/2510.06719