cs.CRMay 19, 2026

Auditing Privacy in Multi-Tenant RAG under Account Collusion

Authors: Florian A. D. Burnat

Organizations: University of Bath, Bath, UK.

Abstract

Multi-tenant RAG services often treat the account as the privacy boundary: each account receives an (εacc,δacc)(\varepsilon_{\text{acc}},δ_{\text{acc}})-DP retrieval guarantee against the tenant index. We show that this framing understates leakage under same-index account collusion. For Gaussian noise-then-select retrieval, kk coordinated same-tenant accounts compose to joint leakage Θ(kεacc)Θ(\sqrt{k}\,\varepsilon_{\text{acc}}), not εacc\varepsilon_{\text{acc}}; we give a matching membership-inference attack and validate the predicted k\sqrt{k} AUC trend in scalar, top-KK, trained-embedder, and production-scale HNSW settings. We then give a verifier-runnable audit protocol that attests noise-then-select retrieval and reports (PASS,εaudit)(\textsf{PASS},\varepsilon_{\text{audit}}) for coalitions up to a declared cap kmaxk_{\max}, without disclosing the index or changing the retrieval decision rule. The claim is retrieval-channel only: generation-channel leakage and adversarially robust coalition-size estimation are complementary audit predicates.

Explore similar work

CardsList
  1. Rent-a-RAG: Embedding-Space Watermarks for Auditing Third-Party RAG

    Sep 3, 2026Alexandr Goultiaev Tolstokorov, Kyriakos Mouratidis, Javad Dogani +1Hievi-RagAlgorithm Auditing