惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Vercel News
Vercel News
博客园 - 【当耐特】
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
小众软件
小众软件
Hugging Face - Blog
Hugging Face - Blog
aimingoo的专栏
aimingoo的专栏
WordPress大学
WordPress大学
G
Google Developers Blog
博客园 - 叶小钗
大猫的无限游戏
大猫的无限游戏
P
Proofpoint News Feed
J
Java Code Geeks
U
Unit 42
云风的 BLOG
云风的 BLOG
阮一峰的网络日志
阮一峰的网络日志
N
Netflix TechBlog - Medium
宝玉的分享
宝玉的分享
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
D
Docker
V
Visual Studio Blog
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
H
Help Net Security
V
V2EX
T
Tailwind CSS Blog

Cryptology ePrint Archive

Fast Isogeny Evaluation on Binary Curves Quick Draw Queries: Lightweight Searchable Public-key Ciphertexts with Hidden Structures via Non-Interactive Key Exchange A Constructive Treatment of Authentication Boolean Arithmetic over $\mathbb{F}_2$ from Group Commutators HAWK with Hint: Algebraic Key Recovery from Side-Channel Leakage Post-Quantum Secure k-Times Traceable Ring Signature A Key Schedule Design and Evaluation under Boundary Round-Key Leakage 2G2T: Constant-Size, Statistically Sound MSM Outsourcing Proximity Signatures Breaking Optimized HQC: The First Cache-Timing Full Decryption Oracle Key-Recovery Attack in Post-Quantum Cryptography Efficient Partially Blind Signatures from Isogenies Evaluating PQC KEMs, Combiners, and Cascade Encryption via Adaptive IND-CPA Testing Using Deep Learning High-Throughput Side-Channel-Protected Stream Cipher Hardware for 6G Systems Efficient e = 3 Threshold RSA via Integer Coordinates for Intel SGX Zeal: PIR for Non-Cooperative Databases VEIL: Lightweight Zero-Knowledge for Hash-Based Multilinear Proof Systems Witness-Indistinguishable Arguments of Knowledge and One-Way Functions The many faces of Schnorr: a touch-up Open Problems in List Decoding and Correlated Agreement Compressed Key Exchange Protocol from Orientations of Large Discriminant Using AVX-512 SPLASH: SPeculative Leakage-Adaptive Secure Hardware An Efficient Identity-Based Blind Signature Scheme from SM9 Efficient Batch Threshold Encryption Using Partial Fraction Techniques A note on the Unsuitability of LIGA for Linkable Ring Signatures: The perils of non-commutativity Verification Facade: Masquerading Insecure Cryptographic Implementations as Verified Code Cryptographic Implications of Worst-Case Hardness of Time-Bounded Kolmogorov Complexity Efficient Merkle-Tree Consistent Accumulator FLOSS: Fast Linear Online Secret-Shared Shuffling Which Privacy Blanket is Optimal in the Shuffle Model? Applications of Bruhat-Chevalley-Renner Decomposition to Metric-Aware Code-Based Cryptography
Practical and Verifiable Encrypted Vector Search for Retr...
Xiangyu Hui, The University of Melbourne · 2026-05-11 · via Cryptology ePrint Archive

Paper 2026/923

Practical and Verifiable Encrypted Vector Search for Retrieval-Augmented Generation

Xingliang Yuan, The University of Melbourne

Olga Ohrimenko, The University of Melbourne

Sid Chi-Kin Chau, CSIRO Data61

Abstract

Retrieval-augmented generation (RAG) systems critically depend on a vector-retrieval stage that selects relevant documents from a large embedding database. When this stage is outsourced to a RAG-as-a-Service provider, query embeddings can reveal sensitive user intent, the outsourced index can leak proprietary corpus information, and a malicious provider can silently manipulate retrieval results. This motivates privacy-preserving verifiable retrieval. The client must be able to confirm that the returned top-$k$ identifiers were produced by faithfully executing an agreed approximate nearest neighbor (ANN) algorithm on a committed encrypted index, while leaking no non-public database information beyond the functional baseline induced by the returned top-$k$ identifiers. We present VeriANN, the \emph{first} encrypted ANN retrieval framework, to our knowledge, that simultaneously achieves \emph{query privacy}, \emph{database confidentiality}, and \emph{verifiability of retrieval results} against malicious servers, under a two-server non-colluding trust model. VeriANN couples distributed-point-function--based PIR over locality-sensitive hashing indexes with authenticated garbled circuits, so that the entire top-$k$ pipeline---bucket decryption, Merkle-root reconstruction, frequency counting, and top-$k$ selection---is executed obliviously and with end-to-end integrity. Making this integration practical requires three new techniques: (i) a sort-based hierarchical oblivious frequency-counting algorithm that enables a distance-free post-processing stage, reducing top-$k$ aggregation from quadratic to quasi-linear complexity; (ii) an end-to-end authenticated verification design that binds the full retrieval pipeline against selective-failure attacks while reducing client-side verification to a single hash check against the published Merkle root; and (iii) a modular state-pool design with an authenticated state-transfer mechanism that dynamically composes precomputed garbled states across query parameters while preserving cross-circuit verifiability. On million-scale corpora, VeriANN achieves second-scale end-to-end latency with KB-scale client-to-server communication, while adding minimal online overhead over a non-verifiable baseline.

BibTeX

@misc{cryptoeprint:2026/923,
      author = {Xiangyu Hui and Xingliang Yuan and Olga Ohrimenko and Sid Chi-Kin Chau},
      title = {Practical and Verifiable Encrypted Vector Search for Retrieval-Augmented Generation},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/923},
      year = {2026},
      url = {https://eprint.iacr.org/2026/923}
}