arXiv

Auditing Privacy in Multi-Tenant RAG under Account Collusion

Title: Auditing Privacy in Multi-Tenant RAG under Account Collusion

Abstract:

Multi-tenant Retrieval-Augmented Generation (RAG) services typically define privacy boundaries at the account level, providing each account with an $(\varepsilon_{\text{acc}},\delta_{\text{acc}})$-differential privacy (DP) guarantee relative to the tenant index. This study demonstrates that such an approach significantly underestimates data leakage when accounts within the same index collude. Specifically, for retrieval mechanisms employing a "noise-then-select" strategy, $k$ coordinated accounts from the same tenant result in a joint leakage rate of $\Theta(\sqrt{k}\,\varepsilon_{\text{acc}})$, rather than the expected $\varepsilon_{\text{acc}}$. We present a corresponding membership-inference attack and empirically confirm the predicted $\sqrt{k}$ Area Under the Curve (AUC) trend across scalar, top-$K$, trained-embedder, and production-scale HNSW configurations. Furthermore, we introduce an audit protocol verifiable by third parties that attests to the integrity of noise-then-select retrieval. This protocol issues a $(\textsf{PASS},\varepsilon_{\text{audit}})$ report for coalitions up to a specified cap $k_{\max}$, without revealing the underlying index or altering the retrieval decision logic. It is important to note that this claim applies exclusively to the retrieval channel; assessing generation-channel leakage and estimating coalition size robustly against adversaries constitute separate, complementary audit objectives.


Source: arXiv Generated at: 2026-06-02 00:00:00 UTC

Related Articles

Law’s Billable Hour Is Being Shredded by AI
Bloomberg

Law’s Billable Hour Is Being Shredded by AI

AI is dismantling the billable hour by automating routine legal tasks. This technological shift threatens the traditiona...

Iran War: Trump Tries to Stop Israel’s Lebanon Push | The Opening Trade 6/2/2026
Bloomberg

Iran War: Trump Tries to Stop Israel’s Lebanon Push | The Opening Trade 6/2/2026

SoftBank in Early Talks to Back $800 Million Agile Robots Round
Bloomberg

SoftBank in Early Talks to Back $800 Million Agile Robots Round

SoftBank is in early talks to back Agile Robots’ $800 million funding round. The Japanese tech giant is currently in pre...

Amundi Is Diversifying Risk Via Commodity Currencies, Gold
Bloomberg

Amundi Is Diversifying Risk Via Commodity Currencies, Gold

Amundi diversifies risk by investing in commodity-linked currencies and gold. This strategy hedges against market volati...

Reuters

Marvell Technology surges after Nvidia's Huang calls it 'next trillion-dollar company'

Marvell Technology shares surged after Nvidia CEO Jensen Huang labeled the firm the “next trillion-dollar company.”

Russia Says It Found Foreign Spyware on Top Officials’ Phones
Bloomberg

Russia Says It Found Foreign Spyware on Top Officials’ Phones

Russia’s FSB claims to have discovered foreign spyware on senior officials’ phones. Moscow attributes the intrusion to h...