acceptodds
Under review as a conference paper at ICLR 2027

Stateful Privacy-Utility Measurement for GraphRAG Evidence

Abstract

Large language models (LLMs) use GraphRAG to support structured reasoning by grounding answers in graph evidence. However, the same evidence that supports an authorized answer may also help reveal protected facts when combined with information from earlier interactions. Editing evidence to reduce this risk can change the generated answer, creating a history-dependent tradeoff between privacy and answer value. Existing work on release control, evidence transformation, and attribution leaves a gap in jointly comparing these effects for complete regenerated outputs under the same prior information. We introduce Stateful Privacy Funnel (SPriF), an offline framework for state-conditioned comparison of complete answer–evidence releases. SPriF regenerates answers for each evidence choice and a matched evidence-removal baseline while fixing the question, history, and other current evidence. A frozen LLM auditor measures incremental privacy cost from complete outputs, while a frozen reader separately measures reference-answer log-likelihood gains under the corresponding evidence contexts. Within a fixed graph-admissible inventory, the conditional funnel identifies the minimum auditor-measured cost meeting a specified reader-value requirement. Experiments on 8,206 evidence transformations across three KGQA benchmarks show that evidence-only scoring can miss minimum- cost complete releases, while relevant history can make history-free choices fail the same reader-value requirement. Under empty history and no other current evidence, post-hoc analysis examines admissible original releases with positive privacy cost and reference-hit answers. In 73.3% of these cases, lower-cost alter- natives also generate reference hits and provide positive reader value. To reduce the cost of scoring candidate releases, we evaluate partial measurement with learned or mean filling. Under a fixed 64-action measurement budget, full-inventory privacy-ranking Spearman reaches ρ ≈ 0.75 with 39.2% fewer test-time direct-scoring calls. Code is available at https://anonymous.4open.science/r/SPriF.

open until 14 Dec 2026

est. 32% chance this paper gets accepted at ICLR 2027.

Reject 68%Accept 32%

What do you think this paper will get?

All positions stay anonymous.

Related papers

Loading the map…

Discussion (0)

Sign in to comment.