2606.24623v1 Jun 23, 2026 cs.CL

다중 에이전트 의미 재작성을 통한 개인 정보 보호 RAG: 맥락 충실도를 저해하지 않으면서 기밀성 확보

Privacy-Preserving RAG via Multi-Agent Semantic Rewriting: Achieving Confidentiality Without Compromising Contextual Fidelity

Derek F. Wong
Derek F. Wong
Citations: 144
h-index: 5
Tao Fang
Tao Fang
Citations: 28
h-index: 2
Yuanhe Zhao
Yuanhe Zhao
Citations: 0
h-index: 0
Tianyu Zhang
Tianyu Zhang
Citations: 0
h-index: 0
Huafei Xing
Huafei Xing
Citations: 0
h-index: 0
Jianbin Li
Jianbin Li
Citations: 0
h-index: 0

Retrieval-Augmented Generation (RAG)은 외부 지식을 통합하여 대규모 언어 모델을 향상시키지만, 민감한 시나리오에 적용할 경우 악의적인 프롬프트를 통해 개인 정보 유출 위험이 있습니다. 이를 해결하기 위해, 우리는 검색된 콘텐츠를 의미 재작성을 통해 정제하는 다중 에이전트 프레임워크를 제안합니다. 개인 정보 추출, 의미 분석 및 재구성에 특화된 세 개의 에이전트를 활용하여, 우리의 접근 방식은 민감한 식별자를 제거하면서도 의미적 핵심을 유지합니다. 우리는 ChatDoctor와 Wiki-PII 데이터셋을 사용하여 6개의 대규모 언어 모델에 대한 프레임워크를 평가했습니다. 실험 결과는 표적 공격 하에서 개인 정보 유출이 크게 감소하는 것을 보여줍니다. 예를 들어, LLaMA-3-8B의 경우 기준 모델에서 144건이었던 표적 정보 노출을 1건으로 줄였습니다. 또한 BLEU-1 점수가 0.122로 맥락 충실도를 높게 유지하여 기존 SAGE 방법의 0.117보다 뛰어난 성능을 보입니다. 마지막으로, 이 프레임워크는 비동기 전처리 모듈로 작동하며 온라인 추론에 추가적인 지연 시간을 발생시키지 않습니다. 모든 재작성은 일회성 오프라인 전처리 단계로 실행됩니다. 연구의 재현성을 높이기 위해, 본 연구의 소스 코드는 https://github.com/foursoils/Privacy-Preserving-RAG 에서 공개적으로 이용할 수 있습니다.

Original Abstract

Retrieval-Augmented Generation enhances large language models by incorporating external knowledge, but deploying it in sensitive scenarios risks privacy leakage via malicious prompts. To address this, we propose a multi-agent framework that sanitizes retrieved content through semantic rewriting. By employing three specialized agents for privacy extraction, semantic analysis, and reconstruction, our approach collaboratively removes sensitive identifiers while preserving the semantic core. We evaluate the framework on the ChatDoctor and Wiki-PII datasets across six large language models. Experimental results demonstrate a significant reduction in privacy leakage under targeted attacks. For instance, we reduced targeted information exposure in LLaMA-3-8B from 144 instances in the baseline to just 1. Furthermore, we maintain strong contextual fidelity with a BLEU-1 score of 0.122, outperforming the existing SAGE method's 0.117. Finally, the framework operates as an asynchronous preprocessing module, introducing no additional latency to online inference, as all rewriting is executed as a one-time offline preprocessing step. To promote reproducibility, the source code of this work is publicly available at https://github.com/foursoils/Privacy-Preserving-RAG.

0 Citations
0 Influential
25.9657359028 Altmetric
0.0 Score
Original PDF
1

No Analysis Report Yet

This paper hasn't been analyzed by Gemini yet.

Log in to request an AI analysis.

댓글

댓글을 작성하려면 로그인하세요.

아직 댓글이 없습니다. 첫 번째 댓글을 남겨보세요!