Securing RAG: A Risk Assessment and Mitigation Framework

📅 2025-05-13
📈 Citations: 0
Influential: 0
📄 PDF
🤖 AI Summary
Integrating sensitive data into Retrieval-Augmented Generation (RAG) systems introduces novel security and privacy risks across the end-to-end pipeline—spanning data preprocessing, storage, retrieval, and large language model (LLM) generation. Method: We systematically identify and characterize the full RAG attack surface, proposing the first RAG-specific attack surface definition methodology. Our structured governance framework integrates domain-specific RAG properties with established standards—including ISO/IEC 27001 and NIST SP 800-53—enabling bidirectional mapping between security controls and compliance requirements. We conduct rigorous risk modeling, attack tree analysis, and RAG pipeline security auditing. Contribution/Results: The work yields a practical, actionable security checklist, a mitigation strategy matrix, and an implementation guide. It directly supports enterprise RAG deployments in achieving compliance with China’s Multi-Level Protection Scheme (MLPS) Level 3 and the GDPR—thereby bridging critical theoretical and practical gaps in RAG security governance.

Technology Category

Application Category

📝 Abstract
Retrieval Augmented Generation (RAG) has emerged as the de facto industry standard for user-facing NLP applications, offering the ability to integrate data without re-training or fine-tuning Large Language Models (LLMs). This capability enhances the quality and accuracy of responses but also introduces novel security and privacy challenges, particularly when sensitive data is integrated. With the rapid adoption of RAG, securing data and services has become a critical priority. This paper first reviews the vulnerabilities of RAG pipelines, and outlines the attack surface from data pre-processing and data storage management to integration with LLMs. The identified risks are then paired with corresponding mitigations in a structured overview. In a second step, the paper develops a framework that combines RAG-specific security considerations, with existing general security guidelines, industry standards, and best practices. The proposed framework aims to guide the implementation of robust, compliant, secure, and trustworthy RAG systems.
Problem

Research questions and friction points this paper is trying to address.

Identify vulnerabilities in RAG pipelines and their attack surfaces
Propose mitigations for security and privacy risks in RAG systems
Develop a framework for secure and compliant RAG implementation
Innovation

Methods, ideas, or system contributions that make the work stand out.

Assesses RAG pipeline vulnerabilities comprehensively
Proposes mitigations for identified security risks
Combines RAG-specific and general security guidelines
🔎 Similar Papers
No similar papers found.
💼 Related Jobs
No related jobs found.
L
Lukas Ammann
Eastern Switzerland University of Applied Sciences (OST), Rapperswil, Switzerland
S
Sara Ott
Eastern Switzerland University of Applied Sciences (OST), Rapperswil, Switzerland
C
Christoph R. Landolt
Eastern Switzerland University of Applied Sciences (OST), Rapperswil, Switzerland; Cyber-Defence Campus, armasuisse Science and Technology, Thun, Switzerland
M
Marco P. Lehmann
Eastern Switzerland University of Applied Sciences (OST), Rapperswil, Switzerland