arXiv:2505.13957cs.CRcs.CL2025-05EMNLP被引 6

首次揭示多模态检索增强生成中的隐私漏洞,攻击者可借查询操纵提取敏感信息。

Beyond Text: Unveiling Privacy Vulnerabilities in Multi-modal Retrieval-Augmented Generation

  • 设计新型组合式结构化提示攻击,在黑盒环境下操纵查询
  • 发现模型会直接生成或间接暴露检索内容中的私密信息
  • 适用于关注多模态AI隐私安全的研究者与开发者

多模态检索增强生成(MRAG)系统通过整合外部多模态数据库提升大模型性能,但引入了未被充分研究的隐私风险。尽管文本型RAG的隐私问题已有研究,多模态数据仍具独特挑战。本文首次系统分析了视觉-语言与语音-语言模态下MRAG的隐私漏洞。采用新颖的组合式结构化提示攻击,在黑盒设置中证明攻击者可通过操控查询提取私密信息。实验表明,大模型不仅会直接生成与检索内容相似的输出,还可能通过描述间接泄露敏感信息,凸显构建鲁棒隐私保护MRAG技术的紧迫性。

原文摘要 · Abstract (English)

Multimodal Retrieval-Augmented Generation (MRAG) systems enhance LMMs by integrating external multimodal databases, but introduce unexplored privacy vulnerabilities. While text-based RAG privacy risks have been studied, multimodal data presents unique challenges. We provide the first systematic analysis of MRAG privacy vulnerabilities across vision-language and speech-language modalities. Using a novel compositional structured prompt attack in a black-box setting, we demonstrate how attackers can extract private information by manipulating queries. Our experiments reveal that LMMs can both directly generate outputs resembling retrieved content and produce descriptions that indirectly expose sensitive information, highlighting the urgent need for robust privacy-preserving MRAG techniques.

多模态隐私安全RAG大模型

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。