English

PRAG: End-to-End Privacy-Preserving Retrieval-Augmented Generation

Cryptography and Security 2026-05-01 v2

Abstract

Retrieval-Augmented Generation (RAG) is essential for enhancing Large Language Models (LLMs) with external knowledge, but its reliance on cloud environments exposes sensitive data to privacy risks. Existing privacy-preserving solutions often sacrifice retrieval quality due to noise injection or only provide partial encryption. We propose PRAG, an end-to-end privacy-preserving RAG system that achieves end-to-end confidentiality for both documents and queries without sacrificing the scalability of cloud-hosted RAG. PRAG features a dual-mode architecture: a non-interactive PRAG-I utilizes homomorphic-friendly approximations for low-latency retrieval, while an interactive PRAG-II leverages client assistance to match the accuracy of non-private RAG. To ensure robust semantic ordering, we introduce Operation-Error Estimation (OEE), a mechanism that stabilizes ranking against homomorphic noise. Experiments on large-scale datasets demonstrate that PRAG achieves competitive recall (72.45%-74.45%), practical retrieval latency, and strong resilience against graph reconstruction attacks while maintaining end-to-end confidentiality. This work confirms the feasibility of secure, high-performance RAG at scale.

Keywords

Cite

@article{arxiv.2604.26525,
  title  = {PRAG: End-to-End Privacy-Preserving Retrieval-Augmented Generation},
  author = {Zhijun Li and Minghui Xu and Huayi Qi and Wenxuan Yu and Tingchuang Zhang and Qiao Zhang and GuangYong Shang and Zhen Ma and Xiuzhen Cheng},
  journal= {arXiv preprint arXiv:2604.26525},
  year   = {2026}
}

Comments

16 pages,6 figures, journal

R2 v1 2026-07-01T12:41:00.224Z