Skip to content
Review Open access

Security and privacy challenges of RAG systems

Aug 2026 · International Journal of Frontiers in Science and Technology Research · 0 citations

Abstract

Retrieval-Augmented Generation (RAG) systems enable robust knowledge integration for large language models but also pose significant security and privacy risks. RAG systems combine two components: a retriever, which searches external data sources for relevant information, and a generator, typically a large language model that uses both the retrieved documents and user queries to produce answers. This study conducts a systematic literature review to assess these challenges using Socio-Technical Systems Theory (which considers interactions among people, technology, and organizational context) and Privacy by Design (PbD, a framework for embedding privacy into system design). Addressing five objectives, the research detects and classifies privacy attacks, evaluates risks throughout the storage, retrieval, and generation phases, scrutinizes measurement methods, contrasts mitigation strategies, and introduces a unified solution. The work culminates in the Integrated Privacy-Preserving RAG Framework (IPRAG), a five-tier architecture supported by a three-phase deployment protocol. This study presents a detailed, actionable approach to constructing secure, privacy-focused RAG systems.

Read PDF