Private-RAG: Answering Multiple Queries with LLMs while Keeping Your Data Private

Fuente: arXiv
Salvato in:
Dettagli Bibliografici
Autori principali: Wu, Ruihan, Wang, Erchi, Zhang, Zhiyuan, Wang, Yu-Xiang
Natura: Preprint
Pubblicazione: 2025
Soggetti:
Accesso online:
Tags: Aggiungi Tag
Nessun Tag, puoi essere il primo ad aggiungerne!!
_version_ 1866908643580968960
author Wu, Ruihan
Wang, Erchi
Zhang, Zhiyuan
Wang, Yu-Xiang
author_facet Wu, Ruihan
Wang, Erchi
Zhang, Zhiyuan
Wang, Yu-Xiang
contents Retrieval-augmented generation (RAG) enhances large language models (LLMs) by retrieving documents from an external corpus at inference time. When this corpus contains sensitive information, however, unprotected RAG systems are at risk of leaking private information. Prior work has introduced differential privacy (DP) guarantees for RAG, but only in single-query settings, which fall short of realistic usage. In this paper, we study the more practical multi-query setting and propose two DP-RAG algorithms. The first, MURAG, leverages an individual privacy filter so that the accumulated privacy loss only depends on how frequently each document is retrieved rather than the total number of queries. The second, MURAG-ADA, further improves utility by privately releasing query-specific thresholds, enabling more precise selection of relevant documents. Our experiments across multiple LLMs and datasets demonstrate that the proposed methods scale to hundreds of queries within a practical DP budget ($\varepsilon\approx10$), while preserving meaningful utility.
format Preprint
id arxiv_https___arxiv_org_abs_2511_07637
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Private-RAG: Answering Multiple Queries with LLMs while Keeping Your Data Private
Wu, Ruihan
Wang, Erchi
Zhang, Zhiyuan
Wang, Yu-Xiang
Machine Learning
Artificial Intelligence
Cryptography and Security
Retrieval-augmented generation (RAG) enhances large language models (LLMs) by retrieving documents from an external corpus at inference time. When this corpus contains sensitive information, however, unprotected RAG systems are at risk of leaking private information. Prior work has introduced differential privacy (DP) guarantees for RAG, but only in single-query settings, which fall short of realistic usage. In this paper, we study the more practical multi-query setting and propose two DP-RAG algorithms. The first, MURAG, leverages an individual privacy filter so that the accumulated privacy loss only depends on how frequently each document is retrieved rather than the total number of queries. The second, MURAG-ADA, further improves utility by privately releasing query-specific thresholds, enabling more precise selection of relevant documents. Our experiments across multiple LLMs and datasets demonstrate that the proposed methods scale to hundreds of queries within a practical DP budget ($\varepsilon\approx10$), while preserving meaningful utility.
title Private-RAG: Answering Multiple Queries with LLMs while Keeping Your Data Private
topic Machine Learning
Artificial Intelligence
Cryptography and Security
url https://arxiv.org/abs/2511.07637