{"id":"https://openalex.org/W4408354281","doi":"https://doi.org/10.1109/icassp49660.2025.10887843","title":"PRESS: Defending Privacy in Retrieval-Augmented Generation via Embedding Space Shifting","display_name":"PRESS: Defending Privacy in Retrieval-Augmented Generation via Embedding Space Shifting","publication_year":2025,"publication_date":"2025-03-12","ids":{"openalex":"https://openalex.org/W4408354281","doi":"https://doi.org/10.1109/icassp49660.2025.10887843"},"language":"en","primary_location":{"id":"doi:10.1109/icassp49660.2025.10887843","is_oa":false,"landing_page_url":"https://doi.org/10.1109/icassp49660.2025.10887843","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"ICASSP 2025 - 2025 IEEE International Conference on Acoustics, Speech and Signal Processing (ICASSP)","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5101721206","display_name":"Jiaming He","orcid":"https://orcid.org/0009-0007-9529-7327"},"institutions":[{"id":"https://openalex.org/I150229711","display_name":"University of Electronic Science and Technology of China","ror":"https://ror.org/04qr3zq92","country_code":"CN","type":"education","lineage":["https://openalex.org/I150229711"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Jiaming He","raw_affiliation_strings":["University of Electronic Science and Technology of China,School of Computer Science and Engineering,China"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"University of Electronic Science and Technology of China,School of Computer Science and Engineering,China","institution_ids":["https://openalex.org/I150229711"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5101474815","display_name":"Cheng Liu","orcid":"https://orcid.org/0000-0002-9700-6569"},"institutions":[{"id":"https://openalex.org/I4210116924","display_name":"Chinese University of Hong Kong, Shenzhen","ror":"https://ror.org/02d5ks197","country_code":"CN","type":"education","lineage":["https://openalex.org/I177725633","https://openalex.org/I180726961","https://openalex.org/I4210116924"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Cheng Liu","raw_affiliation_strings":["The Chinese University of Hong Kong,School of Data Science,Shenzhen,China"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"The Chinese University of Hong Kong,School of Data Science,Shenzhen,China","institution_ids":["https://openalex.org/I4210116924"]}]},{"author_position":"middle","author":{"id":null,"display_name":"Guanyu Hou","orcid":null},"institutions":[{"id":"https://openalex.org/I31595395","display_name":"Chengdu University of Technology","ror":"https://ror.org/05pejbw21","country_code":"CN","type":"education","lineage":["https://openalex.org/I31595395"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Guanyu Hou","raw_affiliation_strings":["Chengdu University of Technology,College of Computer Science and Cyber Security (Oxford Brookes College),China"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Chengdu University of Technology,College of Computer Science and Cyber Security (Oxford Brookes College),China","institution_ids":["https://openalex.org/I31595395"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5066542952","display_name":"Wenbo Jiang","orcid":"https://orcid.org/0000-0002-4592-8094"},"institutions":[{"id":"https://openalex.org/I150229711","display_name":"University of Electronic Science and Technology of China","ror":"https://ror.org/04qr3zq92","country_code":"CN","type":"education","lineage":["https://openalex.org/I150229711"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Wenbo Jiang","raw_affiliation_strings":["University of Electronic Science and Technology of China,School of Computer Science and Engineering,China"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"University of Electronic Science and Technology of China,School of Computer Science and Engineering,China","institution_ids":["https://openalex.org/I150229711"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5100357065","display_name":"Jiachen Li","orcid":"https://orcid.org/0000-0001-9054-1975"},"institutions":[{"id":"https://openalex.org/I196699116","display_name":"Wuhan University of Technology","ror":"https://ror.org/03fe7t173","country_code":"CN","type":"education","lineage":["https://openalex.org/I196699116"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Jiachen Li","raw_affiliation_strings":["Wuhan University of Technology,School of Computer Science and Artificial Intelligence,China"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Wuhan University of Technology,School of Computer Science and Artificial Intelligence,China","institution_ids":["https://openalex.org/I196699116"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":5,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":3.4724,"has_fulltext":false,"cited_by_count":2,"citation_normalized_percentile":{"value":0.91890773,"is_in_top_1_percent":false,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":98,"max":99},"biblio":{"volume":null,"issue":null,"first_page":"1","last_page":"5"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10764","display_name":"Privacy-Preserving Technologies in Data","score":0.9983000159263611,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10764","display_name":"Privacy-Preserving Technologies in Data","score":0.9983000159263611,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11448","display_name":"Face recognition and analysis","score":0.9559999704360962,"subfield":{"id":"https://openalex.org/subfields/1707","display_name":"Computer Vision and Pattern Recognition"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11612","display_name":"Stochastic Gradient Optimization Techniques","score":0.9470000267028809,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.7025314569473267},{"id":"https://openalex.org/keywords/embedding","display_name":"Embedding","score":0.6488888263702393},{"id":"https://openalex.org/keywords/space","display_name":"Space (punctuation)","score":0.49506083130836487},{"id":"https://openalex.org/keywords/internet-privacy","display_name":"Internet privacy","score":0.4370434284210205},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.36065220832824707},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.22856789827346802}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7025314569473267},{"id":"https://openalex.org/C41608201","wikidata":"https://www.wikidata.org/wiki/Q980509","display_name":"Embedding","level":2,"score":0.6488888263702393},{"id":"https://openalex.org/C2778572836","wikidata":"https://www.wikidata.org/wiki/Q380933","display_name":"Space (punctuation)","level":2,"score":0.49506083130836487},{"id":"https://openalex.org/C108827166","wikidata":"https://www.wikidata.org/wiki/Q175975","display_name":"Internet privacy","level":1,"score":0.4370434284210205},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.36065220832824707},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.22856789827346802},{"id":"https://openalex.org/C111919701","wikidata":"https://www.wikidata.org/wiki/Q9135","display_name":"Operating system","level":1,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1109/icassp49660.2025.10887843","is_oa":false,"landing_page_url":"https://doi.org/10.1109/icassp49660.2025.10887843","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"ICASSP 2025 - 2025 IEEE International Conference on Acoustics, Speech and Signal Processing (ICASSP)","raw_type":"proceedings-article"}],"best_oa_location":null,"sustainable_development_goals":[],"awards":[],"funders":[{"id":"https://openalex.org/F4320321001","display_name":"National Natural Science Foundation of China","ror":"https://ror.org/01h0zpd94"}],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":20,"referenced_works":["https://openalex.org/W2101105183","https://openalex.org/W2295124130","https://openalex.org/W2896457183","https://openalex.org/W2951360122","https://openalex.org/W4381930847","https://openalex.org/W4385573325","https://openalex.org/W4386794639","https://openalex.org/W4389519389","https://openalex.org/W4393147129","https://openalex.org/W4400531953","https://openalex.org/W4401042773","https://openalex.org/W4402670423","https://openalex.org/W6682631176","https://openalex.org/W6776073429","https://openalex.org/W6810738896","https://openalex.org/W6846948161","https://openalex.org/W6853773940","https://openalex.org/W6860962984","https://openalex.org/W6863053358","https://openalex.org/W6870479500"],"related_works":["https://openalex.org/W4391375266","https://openalex.org/W2899084033","https://openalex.org/W2748952813","https://openalex.org/W2081900870","https://openalex.org/W2390279801","https://openalex.org/W4391913857","https://openalex.org/W2358668433","https://openalex.org/W4396701345","https://openalex.org/W2376932109","https://openalex.org/W2001405890"],"abstract_inverted_index":{"Retrieval-augmented":[0,53],"generation":[1,54],"(RAG)":[2],"expands":[3],"the":[4,24,34,96,101,106,143,147],"capabilities":[5],"of":[6,43,146],"large":[7],"language":[8,81],"models":[9,82,126],"(LLMs)":[10],"in":[11,66,118],"various":[12],"applications":[13],"by":[14],"integrating":[15],"relevant":[16],"information":[17,35],"retrieved":[18],"from":[19],"external":[20],"data":[21,41],"sources.":[22],"However,":[23],"RAG":[25,67,107,148],"systems":[26],"are":[27],"exposed":[28],"to":[29,39,63,83,109,115],"substantial":[30],"privacy":[31,65,112],"risks":[32],"during":[33],"retrieval":[36],"process,":[37],"leading":[38],"potential":[40,111],"leakage":[42],"private":[44],"information.":[45],"In":[46],"this":[47],"work,":[48],"we":[49,70,89],"present":[50],"a":[51,91],"Privacy-preserving":[52],"via":[55],"Embedding":[56],"Space":[57],"Shifting":[58],"(PRESS),":[59],"systematically":[60],"exploring":[61],"how":[62],"protect":[64],"systems.":[68],"Specifically,":[69],"first":[71],"conduct":[72],"proximal":[73],"policy":[74],"optimization":[75],"(PPO)":[76],"based":[77],"training":[78,86],"on":[79,95,124],"pre-trained":[80],"generate":[84],"target":[85,117],"samples.":[87],"Then":[88],"employ":[90],"purposive":[92],"shift":[93],"fine-tuning":[94],"text":[97],"embedding":[98,119],"model":[99],"with":[100,138],"generated":[102],"samples":[103],"for":[104],"guiding":[105],"system":[108],"map":[110],"leaking":[113],"queries":[114],"safe":[116],"space.":[120],"Extensive":[121],"experimental":[122],"results":[123],"representative":[125],"and":[127],"datasets":[128],"demonstrate":[129],"that":[130],"our":[131],"protection":[132],"method":[133],"achieves":[134],"high":[135,139],"defense":[136],"performance":[137],"efficiency":[140],"while":[141],"keeping":[142],"normal":[144],"functionality":[145],"system.":[149]},"counts_by_year":[{"year":2026,"cited_by_count":2}],"updated_date":"2026-06-13T07:54:00.901334","created_date":"2025-10-10T00:00:00"}
