Revocation Before Rebuild: Semantic Closure for Dense Retrieval Under Tight Handling Windows
Abstract
An authenticated revocation takes effect before a 10M-chunk dense index can be rebuilt: the handling window in our study is one hour, whereas Full Rebuild has a 6.8 h p95 on matched hardware. During this interval, deleting named records leaves answer-bearing mirrors, quotations, migrations, and paraphrases retrievable. We formalize the required serving state as a candidate-bounded semantic revocation closure and instantiate it in RevocEdge-10M, which spans five revocation operators, a 10.2M-chunk Wikipedia stream, and a temporally distinct technical-document stream. PRAU estimates event-time closure from provenance and embedding neighborhoods, applies operator-conditioned admissibility gating, and edits only local document representations in the frozen retrieval space. Ordinary Wikipedia churn favors Partial Rebuild by 1.0 Exposure@20 point, but mirror-heavy, bursty, and authority-skewed events reverse the ordering: PRAU lowers exposure by 2.7, 6.6, and 4.2 points while using rather than GPU-hours. The technical stream reproduces the reversal, with PRAU moving from 0.8 point behind Partial Rebuild on standard updates to 1.6–4.0 points ahead on stress slices; against SISA-Retrieval, the stress-slice advantage reaches 14.8 points on Wikipedia and 14.6 points on technical documents. PRAU publishes in 46.7 min p95 with % one-hour completion and reduces hard-slice answer disclosure to % while retaining % lawful-answer support. These results identify semantic reach as the retrieval-maintenance object that separates efficient updates before rebuild.
Then back it, or bet against it.
Related papers
Open the market on this paper to see 7 more related papers.