EMNLP 20250 citations

Beyond Text: Unveiling Privacy Vulnerabilities in Multi-modal Retrieval-Augmented Generation

Jiankun Zhang, Shenglai Zeng, Jie Ren, Tianqi Zheng, Hui Liu, Xianfeng Tang, Yi Chang

Abstract

Multimodal Retrieval-Augmented Generation (MRAG) systems enhance LMMs by integrating external multimodal databases, but introduce unexplored privacy vulnerabilities. While text-based RAG privacy risks have been studied, multimodal data presents unique challenges. We provide the first systematic analysis of MRAG privacy vulnerabilities across vision-language and speech-language modalities. Using a novel compositional structured prompt attack in a black-box setting, we demonstrate how attackers can extract private information by manipulating queries. Our experiments reveal that LMMs can both directly generate outputs resembling retrieved content and produce descriptions that indirectly expose sensitive information, highlighting the urgent need for robust privacy-preserving MRAG techniques.

BibTeX
@inproceedings{emnlp2025_beyondtextunveil,
  title = {Beyond Text: Unveiling Privacy Vulnerabilities in Multi-modal Retrieval-Augmented Generation},
  author = {Jiankun Zhang and Shenglai Zeng and Jie Ren and Tianqi Zheng and Hui Liu and Xianfeng Tang and Yi Chang},
  booktitle = {EMNLP 2025},
  year = {2025}
}
Beyond Text: Unveiling Privacy Vulnerabilities in Multi-modal Retrieval-Augmented Generation · EMNLP 2025