Quantization Enables Private Dense Retrieval against Malicious Service Providers
Organizations: École de technologie supérieure and Mila · Eurecom · Université du Québec à Montréal
Abstract
Dense retrieval, the key component of Retrieval Augmented Generation (RAG), retrieves the most relevant documents by comparing dense vector representations of queries and passages from a large corpus. In privacy-sensitive applications, the server observes the query and controls which evidence is returned, creating both confidentiality and integrity risks. We formulate private dense retrieval as providing query privacy and retrieval integrity against a malicious server, and develop a two-round cryptographic protocol that provides both guarantees. Our protocol reduces private and verifiable retrieval to multiplication of a committed matrix by an encrypted vector and uses low-bit quantization to make this computation practical. We evaluate the resulting trade-off between cryptographic cost, retrieval quality, and downstream RAG accuracy across six embedding models, four language models, and corpora of up to 2.68 million passages. Our results show that, with a clipped quantizer, three-bit quantization largely preserves retrieval quality and downstream accuracy, while a private query over a corpus the size of a clinical reference requires one to three minutes of server time. These results suggest that private dense retrieval is already practical for moderately sized, privacy-sensitive corpora when minute-scale latency is acceptable.
Figures & tables
| Privacy | Integrity | Exactness | Malicious security | |
|---|---|---|---|---|
| Tiptoe ( Henzinger et al., 2023 ) | ||||
| PIR-RAG ( Wang et al., 2025 ) | ||||
| PPMI ( Bae et al., 2025 ) | ||||
| Compass ( Zhu et al., 2024 ) | ||||
| VeriRAG ( Lin et al., 2026 ) | ||||
| zkRAG ( Jiang et al., 2026 ) |
| / | |||||
|---|---|---|---|---|---|
| Corpus | Round 1: | Round 2: | Client | Server | $/query |
| NFCorpus ( chunks) | ms / ms | s / s | / | ||
| SciFact ( chunks) | ms / ms | s / s | / | ||
| ms / s | s / s | / | |||
| s / s | s / s | / | |||
| s / min | min / min | / | |||
| SciFact | SciFact | BioASQ | NQ , M | |||||
|---|---|---|---|---|---|---|---|---|
| BGE | arctic | BGE | arctic | BGE | arctic | BGE | arctic | |
| closed book | ||||||||
| gold context | ||||||||
| float | ||||||||
Appendix figures & tables10 assets
Supplementary material from the paper’s appendix.
Appendix
| Round | |||||||
|---|---|---|---|---|---|---|---|
| Round 1 ( ) | |||||||
| Round 1 ( ) | |||||||
| Round 1 ( ) | |||||||
| Round 2 |
| Endpoint | Encoder | float | |||
|---|---|---|---|---|---|
| phi-4 (14B) | |||||
| SciFact | BGE | † | † | ∗ | |
| SciFact | arctic | † | † | † | |
| SciFact | BGE | † | † | ∗ | |
| SciFact | arctic | † | † | ∗ | |
| BioASQ | BGE | † | † | † | |
| Endpoint | Encoder | Unit | float | |||
|---|---|---|---|---|---|---|
| SciFact | BGE | abstracts | † | † | ∗ | |
| chunks | † | ∗ | ∗ | |||
| SciFact | arctic | abstracts | † | † | † | |
| chunks | † | † | † | |||
| SciFact | BGE | abstracts | † | † | ∗ | |
| chunks | † | † | ∗ |
| SciFact | NFCorpus | ||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| low-bit | conventional | low-bit | conventional | ||||||||||
| arctic | Cohere | BGE | mxbai | e5 | gte | arctic | Cohere | BGE | mxbai | e5 | gte | ||
| SciFact | NFCorpus | ||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|
| Encoder | low-bit | float | ret. | ret. | top-1 | top-1 | float | ret. | ret. | top-1 | top-1 |
| arctic-embed-l-v2.0 | |||||||||||
| Cohere embed-v3 | |||||||||||
| bge-large-en-v1.5 | |||||||||||
| mxbai-embed-large-v1 | |||||||||||
| e5-large-v2 | |||||||||||
| Encoder | ret. (%) | top-1 | ret. (%) | top-1 |
|---|---|---|---|---|
| SciFact | ||||
| arctic-embed-l-v2.0 | ||||
| Cohere embed-v3 | ||||
| bge-large-en-v1.5 | ||||
| mxbai-embed-large-v1 | ||||
| Encoder | Corpus | top dim. (%) | gap | gap/noise | top-1 | ||
|---|---|---|---|---|---|---|---|
| arctic-embed-l-v2.0 | SciFact | ||||||
| Cohere embed-v3 | SciFact | ||||||
| bge-large-en-v1.5 | SciFact | ||||||
| mxbai-embed-large-v1 | SciFact | ||||||
| e5-large-v2 | SciFact | ||||||
| gte-large | SciFact |
| Trained for low-bit readout | Conventional | |||||
| arctic | Cohere | BGE | mxbai | e5 | gte | |
| SciFact | ||||||
| Recall@5 retained (%) | |||||
|---|---|---|---|---|---|
| Encoder | Recall@5 (float) | ||||
| arctic-embed-l-v2.0 | |||||
| bge-large-en-v1.5 | |||||
| nDCG@10 ret. (%) | required | |||
|---|---|---|---|---|
| Encoder | (top- ) | |||
| arctic-embed-l-v2.0 | ||||
| bge-large-en-v1.5 | ||||