about
RAG with Differential Privacy (arxiv.org)
2 points by ngrislain on Jan 10, 2025 | hide | past | pdf | discuss on HN

In plain words: When a chatbot pulls private documents into its answer, it can accidentally reveal them. This approach adds carefully controlled randomness while each word is generated, so no single document can be traced, and it proved workable for pulling general knowledge out of personal data.

Abstract

Retrieval-Augmented Generation (RAG) has emerged as the dominant technique to provide \emph{Large Language Models} (LLM) with fresh and relevant context, mitigating the risk of hallucinations and improving the overall quality of responses in environments with large and fast moving knowledge bases. However, the integration of external documents into the generation process raises significant privacy concerns. Indeed, when added to a prompt, it is not possible to guarantee a response will not inadvertently expose confidential data, leading to potential breaches of privacy and ethical dilemmas. This paper explores a practical solution to this problem suitable to general knowledge extraction from personal data. It shows \emph{differentially private token generation} is a viable approach to private RAG.

Nicolas Grislain
arXiv:2412.19291 · cs.LG, cs.AI, cs.CR · submitted Dec 26, 2024 · updated Jan 22, 2025
abstract · pdf · html

add comment on HN