DuetER: Efficient Dual-Path Encrypted Search for Retrieval-Augmented Generation
Abstract
Outsourcing retrieval-augmented generation (RAG) corpora and indexes to untrusted clouds creates a three-way conflict among retrieval fidelity, data confidentiality and scalability. Existing privacy-preserving RAG solutions either rely on single-path retrieval with inherently limited recall, or impose prohibitive cryptographic overhead. We propose DuetER, an efficient dual-path encrypted retrieval architecture that maps dense semantic similarity and compressed BM25 proxy onto a unified Euclidean ranking interface. Path-specific keyed indexes prune the search space to eliminate full‑corpus scans, the cloud ranks encrypted candidates, and the client recomputes native scores before lightweight query-adaptive fusion. DuetER designs compartment conditional approximate distance‑preserving encryption (\DPE), which enables efficient ciphertext ranking without directly exposing the single global comparison frame of conventional DPE. Independent aliases further remove direct identifier equality across paths. Experiments on real-world datasets show that DuetER outperforms both single-path variants and improves recall over state-of-the-art (SOTA) baselines. At million‑scale corpora, cloud‑side query processing completes in roughly 1 second. These results establish a measured utility–efficiency–leakage architecture for scalable dual-path RAG. Our code is available on https://anonymous.4open.science/r/DuetER-0D0E.
est. 32% chance this paper gets accepted at ICLR 2027.
What do you think this paper will get?
All positions stay anonymous.