Securing RAG: A Risk Assessment and Mitigation Framework
arXiv:2505.08728 · doi:10.1109/SDS66131.2025.00024
Abstract
Retrieval Augmented Generation (RAG) has emerged as the de facto industry standard for user-facing NLP applications, offering the ability to integrate data without re-training or fine-tuning Large Language Models (LLMs). This capability enhances the quality and accuracy of responses but also introduces novel security and privacy challenges, particularly when sensitive data is integrated. With the rapid adoption of RAG, securing data and services has become a critical priority. This paper first reviews the vulnerabilities of RAG pipelines, and outlines the attack surface from data pre-processing and data storage management to integration with LLMs. The identified risks are then paired with corresponding mitigations in a structured overview. In a second step, the paper develops a framework that combines RAG-specific security considerations, with existing general security guidelines, industry standards, and best practices. The proposed framework aims to guide the implementation of robust, compliant, secure, and trustworthy RAG systems.
8 pages, 3 figures, Sara Ott and Lukas Ammann contributed equally. This work has been submitted to the IEEE for possible publication
References in corpus (15)
- A Survey on Hallucination in Large Language Models: Principles, Taxonomy, Challenges, and Open Questions
- Retrieval-Augmented Generation for Large Language Models: A Survey
- Gemini 1.5: Unlocking multimodal understanding across millions of tokens of context
- The Power of Noise: Redefining Retrieval for RAG Systems
- Self-RAG: Learning to Retrieve, Generate, and Critique through Self-Reflection
- Evaluating Large Language Models: A Comprehensive Survey
- Is My Data in Your Retrieval Database? Membership Inference Attacks Against Retrieval Augmented Generation
- Transferable Embedding Inversion Attack: Uncovering Privacy Risks in Text Embeddings without Model Queries
- Feedback-Guided Extraction of Knowledge Base from Retrieval-Augmented LLM Applications
- Mitigating the Privacy Issues in Retrieval-Augmented Generation (RAG) via Pure Synthetic Data
- SecGenAI: Enhancing Security of Cloud-based Generative AI Applications within Australian Critical Technologies of National Interest
- Multi-Head RAG: Solving Multi-Aspect Problems with LLMs
- Black-Box Opinion Manipulation Attacks to Retrieval-Augmented Generation of Large Language Models
- On the Privacy Risk of In-context Learning
- HijackRAG: Hijacking Attacks against Retrieval-Augmented Large Language Models