Mask-based Membership Inference Attacks for Retrieval-Augmented Generation
Mingrui Liu, Sixiao Zhang, Cheng Long
Abstract
Retrieval-Augmented Generation (RAG) has been an effective approach to mitigate hallucinations in large language models (LLMs) by incorporating up-to-date and domain-specific knowledge. Recently, there has been a trend of storing up-to-date or copyrighted data in RAG knowledge databases instead of using it for LLM training. This practice has raised concerns about Membership Inference Attacks (MIAs), which aim to detect if a specific target document is stored in the RAG system's knowledge database so as to protect the rights of data producers. While research has focused on enhancing the trustworthiness of RAG systems, existing MIAs for RAG systems remain largely insufficient. Previous work either relies solely on the RAG system's judgment or is easily influenced by other documents or the LLM's internal knowledge, which is unreliable and lacks explainability. To address these limitations, we propose a Mask-Based Membership Inference Attacks (MBA) framework. Our framework first employs a masking algorithm that effectively masks a certain number of words in the target document. The masked text is then used to prompt the RAG system, and the RAG system is required to predict the mask values. If the target document appears in the knowledge database, the masked text will retrieve the complete target document as context, allowing for accurate mask prediction. Finally, we adopt a simple yet effective threshold-based method to infer the membership of target document by analyzing the accuracy of mask prediction. Our mask-based approach is more documentspecific, making the RAG system's generation less susceptible to distractions from other documents or the LLM's internal knowledge. Extensive experiments demonstrate the effectiveness of our approach compared to existing baseline models. CCS Concepts • Computing methodologies → Information extraction; • Security and privacy → Human and societal aspects of security and privacy.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 76ebf5a1-ab6f-472a-b391-0eb9f430aaffCited by top-tier papers10
- ImageSentinel: Protecting Visual Datasets from Unauthorized Retrieval-Augmented Image GenerationZiyuan Luo, Yangyi Zhao, Ka Chun Cheung, Simon See et al.NeurIPS 2025 · 5 citations
- Five Queries Are Enough: Query-Efficient and Surrogate-Free Membership Inference Attacks on RAG via EntailmentNguyen Linh Bao Nguyen, Wanlun Ma, Viet Vo, Alsharif Abuadbba et al.USENIX Security 2026 · 4 citations
- MrM: Black-Box Membership Inference Attacks Against Multimodal RAG SystemsPeiru Yang, Jinhua Yin, Haoran Zheng, Xueying Bai et al.AAAI 2026 · 3 citations
- Connect the Dots: Knowledge Graph–Guided Crawler Attack on Retrieval-Augmented Generation SystemsMengyu Yao, Ziqi Zhang, Ning Luo, Shaofei Li et al.USENIX Security 2026 · 3 citations
- RedVisor: Reasoning-Aware Prompt Injection Defense via Zero-Copy KV Cache ReuseMingrui Liu, Sixiao Zhang, Cheng Long, Kwok Yan LamICML 2026 · 2 citations
Builds on13
- Language Models are Few-Shot LearnersTom B. Brown, Benjamin Mann, Nick Ryder, Melanie Subbiah et al.NeurIPS 2020 · 64,255 citations
- Retrieval-Augmented Generation for Knowledge-Intensive NLP TasksPatrick Lewis, Ethan Perez, Aleksandra Piktus, Fabio Petroni et al.NeurIPS 2020 · 19,162 citations
- Membership Inference Attacks Against Machine Learning ModelsReza Shokri, Marco Stronati, Congzheng Song, Vitaly ShmatikovS&P 2017 · 5,137 citations
- Extracting Training Data from Large Language ModelsNicholas Carlini, Florian Tramèr, Eric Wallace, Matthew Jagielski et al.USENIX Security 2021 · 2,866 citations
- Generalization through Memorization: Nearest Neighbor Language ModelsUrvashi Khandelwal, Omer Levy, Dan Jurafsky, Luke Zettlemoyer et al.ICLR 2020 · 1,038 citations
Related papers
- Riddle Me This! Stealthy Membership Inference for Retrieval-Augmented GenerationAli Naseh, Yuefeng Peng, Anshuman Suri, Harsh Chaudhari et al.CCS 2025
- DCMI: A Differential Calibration Membership Inference Attack Against Retrieval-Augmented GenerationXinyu Gao, Xiangtao Meng, Yingkai Dong, Zheng Li et al.CCS 2025
- Open Schrödinger's Closed Box: Identifying Retrieval Augmented Generation in API-Accessible Large Language Model ServicesYukun Jiang, Xinyue Shen, Michael Backes, Zheng Li et al.ACL 2026
- WARP: A Word-Level Backdoor Attack Targeting RAG Systems via Retrieval Corpus PoisoningHui Liu, Yibo Zhou, Liguo Dong, Weidong Li et al.KDD 2026
- RAG-WM: An Efficient Black-Box Watermarking Approach for Retrieval-Augmented Generation of Large Language ModelsPeizhuo Lv, Mengjie Sun, Hao Wang, XiaoFeng Wang et al.CCS 2025
