为敏感领域设计可保护数据的对话检索增强系统
Sensitivity-Aware Retrieval-Augmented Intent Clarification
- 引入攻击模型,明确需防护的敏感信息类型
- 在检索层设计感知敏感度的防御机制,防止信息泄露
- 提出评估方法,在安全与系统性能间权衡
在对话式搜索系统中,理解并澄清复杂查询背后的意图至关重要。本文从探索性搜索范式出发,认为用户通过迭代的选择、探索和检索过程,将模糊需求转化为正式意图。在大语言模型缺乏参数化知识的领域,引入检索步骤(即检索增强意图澄清)可显著提升澄清效果。然而,在医疗、政府(如信息公开申请)或法律等敏感领域,检索数据库可能包含需保护的信息。为此,本文提出三步研究方案:1)定义攻击模型,明确防护目标;2)在检索层面设计敏感度感知的防御机制;3)开发评估方法,衡量保护水平与系统效用之间的权衡。
原文摘要 · Abstract (English)
In conversational search systems, a key component is to determine and clarify the intent behind complex queries. We view intent clarification in light of the exploratory search paradigm, where users, through an iterative, evolving process of selection, exploration and retrieval, transform a visceral or conscious need into a formalized one. Augmenting the clarification component with a retrieval step (retrieval-augmented intent clarification) can seriously enhance clarification performance, especially in domains where Large Language Models (LLMs) lack parametric knowledge. However, in more sensitive domains, such as healthcare, government (e.g. FOIA search) or legal contexts, the retrieval database may contain sensitive information that needs protection. In this paper, we explore the research challenge of developing a retrieval-augmented conversational agent that can act as a mediator and gatekeeper for the sensitive collection. To do that, we also need to know what we are protecting and against what. We propose to tackle this research challenge in three steps: 1) define an attack model, 2) design sensitivity-aware defenses on the retrieval level and 3) develop evaluation methods to measure the trade-off between the level of protection and the system's utility.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。