Abstract
Retrieval-based augmentation enhances the capabilities of large language models (LLMs) by incorporating external knowledge into the response generation process. However, existing retrieval-augmented frameworks often lack fine-grained access control and risk exposing sensitive content, particularly in voice-based interactive systems where queries are open-ended and personalized. This risk becomes especially pronounced when the retrieved information includes proprietary or user-specific data. To mitigate these challenges, we propose PrivRAG, a privacy-preserving retrieval protocol that integrates access control and response-level privacy protection throughout the generation pipeline. Specifically, each document in the knowledge base is assigned an attribute-based access policy represented as a logical tree, ensuring that only authorized users can retrieve relevant content. The interactions between user and LLM-driven assistant is modeled as a multi-turn process, where user attributes are inferred through probabilistic reasoning over observed responses. Based on these inferred attributes, the system selectively accesses permitted knowledge segments and generates responses accordingly. To further protect sensitive content, the response is transformed using a formal privacy-preserving mechanism that combines calibrated noise injection for numerical fields with semantic generalization for textual entities. Empirical evaluations on synthetic interactions demonstrate that PrivRAG effectively enforces access control while preserving user privacy, with minimal degradation in response quality across voice-based use cases.
| Original language | English |
|---|---|
| Pages (from-to) | 1054-1061 |
| Number of pages | 8 |
| Journal | Proceedings of the IEEE International Conference on Trust, Security and Privacy in Computing and Communications, TrustCom |
| Issue number | 2025 |
| DOIs | |
| State | Published - 2025 |
| Event | 24th IEEE International Conference on Trust, Security and Privacy in Computing and Communications, TrustCom 2025 - Guiyang, China Duration: 14 Nov 2025 → 17 Nov 2025 |
Keywords
- Access Control
- Bayesian Inference
- Privacy-Preserving
- Retrieval-Augmented Generation
Fingerprint
Dive into the research topics of 'PrivRAG: A Privacy-Preserving Retrieval-Augmented Generation Protocol for LLM-Driven Voice Assistants'. Together they form a unique fingerprint.Cite this
- APA
- Author
- BIBTEX
- Harvard
- Standard
- RIS
- Vancouver