Mitigating the Privacy Issues in Retrieval-Augmented Generation (RAG) via Pure Synthetic Data

Shenglai Zeng,Jiankun Zhang,Pengfei He,Jie Ren,Tianqi Zheng,Hanqing Lu,Han Xu,Hui Liu,Yue Xing,Jiliang Tang
2024-06-21
Abstract:Retrieval-augmented generation (RAG) enhances the outputs of language models by integrating relevant information retrieved from external knowledge sources. However, when the retrieval process involves private data, RAG systems may face severe privacy risks, potentially leading to the leakage of sensitive information. To address this issue, we propose using synthetic data as a privacy-preserving alternative for the retrieval data. We propose SAGE, a novel two-stage synthetic data generation paradigm. In the stage-1, we employ an attribute-based extraction and generation approach to preserve key contextual information from the original data. In the stage-2, we further enhance the privacy properties of the synthetic data through an agent-based iterative refinement process. Extensive experiments demonstrate that using our synthetic data as the retrieval context achieves comparable performance to using the original data while substantially reducing privacy risks. Our work takes the first step towards investigating the possibility of generating high-utility and privacy-preserving synthetic data for RAG, opening up new opportunities for the safe application of RAG systems in various domains.
Cryptography and Security
What problem does this paper attempt to address?
The paper aims to address the issue of privacy leakage faced by Retrieval-Augmented Generation (RAG) systems when handling private data. Specifically, when the retrieval process of RAG systems involves private data, it may lead to the leakage of sensitive information, thereby limiting the application scope of RAG systems, especially in sensitive fields such as healthcare. To solve this problem, the authors propose a method of using synthetic data to replace the original data. By generating synthetic data that retains key contextual information while protecting privacy, the risk of information leakage is reduced. This method not only maintains the performance of RAG systems under the premise of ensuring data privacy but also opens up new possibilities for the secure application of RAG systems in various fields. The specific method proposed in the paper is called SAGE (Synthetic Attribute-based Generation with Agent-based refinement), which includes two stages: the first stage involves attribute extraction and generation of synthetic data, and the second stage further enhances data privacy protection through agent-based interactive refinement. Experimental results show that when using synthetic data generated by SAGE as retrieval data, its performance is comparable to that of using original data, while significantly reducing privacy risks.