Security, Governance and Platform · Staff
The PDF looks redacted. Why did RAG reveal the hidden text?
Take a few minutes to form your approach. Then open a worked answer and compare the decisions.
Reveal a worked answer
A legal team opens a PDF and sees black rectangles over names and account numbers. They upload it to the knowledge base. A user later asks a general question and the assistant quotes a covered account number. The first thing to check is whether the PDF was actually redacted or merely painted over.
PDFs can contain text objects, images, annotations and other layers. A black shape drawn on top of a text object changes what a viewer displays, but the underlying text can remain in the file for selection, search or extraction. A text-first RAG parser may recover it without doing OCR at all. The PDF Association warns that covering information with a black bar is not permanent removal. Adobe's redaction guidance distinguishes a proper redaction and sanitization workflow that removes visible and hidden content.
The trust boundary is ingestion, not the model's final wording. Test the exact uploaded bytes with the same extractor the pipeline uses, and also inspect attachments, metadata, annotations and alternate text representations. If restricted content survives extraction, do not index or embed that file for broad access. Delete affected index entries and cached chunks, then rebuild from an approved, properly sanitized source revision. Check whether generated summaries or downstream exports already copied the text elsewhere.
Simply telling the model “do not reveal redacted text” cannot undo the fact that the text entered retrieval. Rasterizing the visually blacked-out page can remove selectable text from that particular output, but it is a workaround with risks: image layers, metadata, attachments and source revision handling still need checking. A validated redaction process with extraction-based verification is safer. For sensitive uploads, run a pre-ingestion check that searches for known redacted spans when available and flags suspicious overlays or incomplete redaction annotations for review.
An interviewer may say that OCR cannot see through a black bar. That is true for OCR on the flattened visible image. The leak here comes from the PDF's retained text objects or hidden content, which a different extraction path can read. The same document can be visually safe to a person and unsafe to a machine reader.
Continue reading
Related questions
Read beyond the question
Explore more security, governance and platform
Follow another question in this area, or search the complete Question Library.
Browse this area →Browse Question Library →