Advanced Search
    Tan Xue, Zheng Yi, Zhang Yunruo, Chen Yiran, Chen Ping, Xue Xiangyang. Anti-Mapping Representation Perturbation for RAG Sensitive Information ProtectionJ. Journal of Computer Research and Development. DOI: 10.7544/issn1000-1239.202550713
    Citation: Tan Xue, Zheng Yi, Zhang Yunruo, Chen Yiran, Chen Ping, Xue Xiangyang. Anti-Mapping Representation Perturbation for RAG Sensitive Information ProtectionJ. Journal of Computer Research and Development. DOI: 10.7544/issn1000-1239.202550713

    Anti-Mapping Representation Perturbation for RAG Sensitive Information Protection

    • Retrieval-augmented generation (RAG) systems extend the capability of large language models by incorporating external knowledge databases, enabling more accurate and up-to-date responses. However, this integration also introduces a novel privacy vulnerability: mapping attacks (MA), which aim to infer whether a specific private fragment is indexed in the retrieval database and to uncover its retrieval behavior. Such attacks exploit both embedding-level signals and retrieval dynamics, posing a serious threat to sensitive data protection in RAG pipelines. Despite the growing awareness of privacy risks in RAG systems, there is currently no dedicated defense mechanism specifically designed to mitigate mapping attacks. We introduce AMRP-SIP, a dual-randomization framework that concurrently protects both embeddings of the documents and retrieval traces, while preserving state-of-the-art utility. AMRP-SIP comprises three lightweight stages. First, a Random Orthogonal Projection compresses each query and document into a low-dimensional latent space, hiding raw embeddings and reducing downstream noise. Second, Adaptive Differential Privacy injects cluster-adaptive Gaussian noise, ensuring (ε, δ) fragment-level privacy. Third, a score-dropout layer introduces randomness by perturbing similarity scores with noise and probabilistically dropping a portion of the retrieved documents with probability p, thereby obfuscating the retrieval trajectory. Experiments on Wiki-40B, PubMed, and IP-Database demonstrate that AMRP-SIP reduces the AUC of membership inference attacks (MIA) from 0.75 to 0.27, while maintaining competitive performance in downstream RAG tasks.
    • loading

    Catalog

      Turn off MathJax
      Article Contents

      /

      DownLoad:  Full-Size Img  PowerPoint
      Return
      Return