arXiv:2510.07728cs.IRcs.CL2025-10被引 16

提出检测RAG系统数据盗用的新方法,保护AI生成内容的知识产权。

Who Stole Your Data? A Method for Detecting Unauthorized RAG Theft

  • 设计双层水印技术,在语义和词汇层面嵌入保护信号。
  • 在多种查询量和参数下验证有效,抗对抗性规避攻击。
  • 适用于需防范数据盗用的AI研发与内容创作场景。

检索增强生成(RAG)通过缓解大语言模型的幻觉和信息过时问题,提升生成质量,但也导致大规模未经授权的数据窃取。本文提出两项关键贡献:首先,构建了名为RPD的新型数据集,涵盖多样专业领域和写作风格,弥补现有资源不足;其次,设计双层水印系统,在语义与词汇层面嵌入保护信号,并配套采用统计假设检验的询问-侦测框架,聚合证据进行判定。大量实验表明,该方法在不同查询量、防御提示和检索参数下均表现有效,且对对抗性规避手段具备鲁棒性。本工作为检索增强型AI系统的知识产权保护奠定了基础框架。

原文摘要 · Abstract (English)

Retrieval-augmented generation (RAG) enhances Large Language Models (LLMs) by mitigating hallucinations and outdated information issues, yet simultaneously facilitates unauthorized data appropriation at scale. This paper addresses this challenge through two key contributions. First, we introduce RPD, a novel dataset specifically designed for RAG plagiarism detection that encompasses diverse professional domains and writing styles, overcoming limitations in existing resources. Second, we develop a dual-layered watermarking system that embeds protection at both semantic and lexical levels, complemented by an interrogator-detective framework that employs statistical hypothesis testing on accumulated evidence. Extensive experimentation demonstrates our approach's effectiveness across varying query volumes, defense prompts, and retrieval parameters, while maintaining resilience against adversarial evasion techniques. This work establishes a foundational framework for intellectual property protection in retrieval-augmented AI systems.

RAG安全数据盗用水印技术知识产权

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。