2607004625
  • Open Access
  • Article

Trustworthy Deployment of LLM-Based RAG Systems for Small Businesses: A Security and Confidence-Aware Framework

  • Jiazhu Xie ‡,   
  • Qingqing Wang ‡,   
  • Bowen Li,   
  • Ziqi Xu,   
  • Fengling Han *

Received: 15 Apr 2026 | Revised: 09 Jul 2026 | Accepted: 13 Jul 2026 | Published: 07 Aug 2026

Abstract

Small and medium-sized enterprises (SMEs) are increasingly deploying Large Language Model (LLM)-based agentic systems to support customer service and internal knowledge management. However, practical deployment of retrievalaugmented generation (RAG) systems continues to be challenging due to promptinjection risks, unreliable confidence estimation, and limited operational resources in real-world SME environments. This paper presents a secure and confidenceaware deployment framework for SME-oriented RAG systems. The proposed platform integrates layered prompt-injection defences with structured confidenceaware outputs to support more reliable and controlled agentic behaviour during deployment. Rather than treating trustworthiness as a model-level metric, we frame it as a system-level property emerging from the interaction between security filtering, confidence handling, and downstream response control. We evaluate the framework through a real-world e-commerce customer-support deployment operating under realistic SME infrastructure constraints. Experimental results show that the proposed deployment strategy improves prompt-injection robustness while substantially enhancing confidence calibration through structured prompting. The calibrated confidence signals provide useful uncertainty information that may support confidenceaware response handling during deployment. Results across both in-domain and out-ofdomain prompt-injection benchmarks indicate that combining layered security filtering with confidence-aware deployment mechanisms can reduce the risk of overconfident and unsafe responses while remaining practical for lightweight SME infrastructure environments. Experimental results indicate that the proposed deployment pipeline improves prompt-injection robustness while providing more reliable confidence estimates. These improvements were consistently observed across both in-domain and public benchmarks.

References 

  • 1.

    Gao, Y.; Xiong, Y.; Gao, X.; et al. Retrieval-Augmented Generation for Large Language Models: A Survey. arXiv 2024, arXiv:2312.10997.

  • 2.

    Schick, T.; Dwivedi-Yu, J.; Dess`ı, R.; et al. Toolformer: Language Models Can Teach Themselves to Use Tools. In Proceedings of the Advances in Neural Information Processing Systems (NeurIPS), vol. 36. Curran Associates, Inc., 2023, pp. 68539–68551.

  • 3.

    Liu, Y.; Deng, G.; Li, Y.; et al. Prompt Injection attack against LLM-integrated Applications. arXiv 2024, arXiv:2306.05499.

  • 4.

    Guo, C.; Pleiss, G.; Sun, Y.; et al. On Calibration of Modern Neural Networks. In Proceedings of the 34th International Conference on Machine Learning, Sydney, NSW, Australia, 6–11 August 2017; pp. 1321–1330.

  • 5.

    Jiang, Z.; Araki, J.; Ding, H.; et al. How Can We Know When Language Models Know? On the Calibration of Language Models for Question Answering. Trans. Assoc. Comput. Linguist. 2021, 9, 962–977, https://doi.org/10.1162/tacl_a_00407.

  • 6.

    Chhikara, P. Mind the Confidence Gap: Overconfidence, Calibration, and Distractor Effects in Large Language Models. arXiv 2025, arXiv:2502.11028.

  • 7.

    Kadavath, S.; Conerly, T.; Askell, A.; et al. Language Models (Mostly) Know What They Know. arXiv 2022, arXiv:2207.05221.

  • 8.

    Wang, X.; Wei, J.; Schuurmans, D.; et al. Self-Consistency Improves Chain of Thought Reasoning in Language Models. In Proceedings of the International Conference on Learning Representations (ICLR), Kigali, Rwanda, 1–5 May 2023.

  • 9.

    Sclar, M.; Choi, Y.; Tsvetkov, Y.; et al. Quantifying Language Models’ Sensitivity to Spurious Features in Prompt Design or: How I Learned to Start Worrying About Prompt Formatting. In Proceedings of the Twelfth International Conference on Learning Representations (ICLR), Vienna, Austria, 7–11 May 2024.

  • 10.

    Jang, J.; Ye, S.; Seo, M. Can Large Language Models Truly Understand Prompts? A Case Study with Negated Prompts. In Proceedings of Machine Learning Research, Proceedings of The 1st Transfer Learning for Natural Language Processing Workshop, New Orleans, LA, USA, 3 December 2022; PMLR: Cambridge, MA, USA, 2023; Volume 203; pp. 52–62.

  • 11.

    Xie, J.; Li, B.; Fu, H.; et al. Securing LLM-as-a-Service for Small Businesses: An Industry Case Study of a Distributed Chatbot Deployment Platform. In Proceedings of the 2026 Australasian Information Security Conference, Melbourne, VIC, Australia, 9–13 February 2026.

  • 12.

    Li, R.; Chen, M.; Hu, C.; et al. GenTel-Safe: A Unified Benchmark and Shielding Framework for Defending Against Prompt Injection Attacks. arXiv 2024, arXiv:2409.19521.

  • 13.

    Panigrahi, R.R.; Shrivastava, A.K.; Qureshi, K.M.; et al. AI Chatbot Adoption in SMEs for Sustainable Manufacturing Supply Chain Performance: A Mediational Research in an Emerging Country. Sustainability 2023, 15, 13743. https://doi.org/10.3390/su151813743.

  • 14.

    Sharma, S.; Singh, G.; Islam, N.; et al. Why Do SMEs Adopt Artificial Intelligence-Based Chatbots? IEEE Trans. Eng. Manag. 2024, 71, 1773–1786. https://doi.org/10.1109/TEM.2022.3203469.

  • 15.

    Lewis, P.; Perez, E.; Piktus, A.; et al. Retrieval-augmented generation for knowledge-intensive NLP tasks. In Proceedings of the 34th International Conference on Neural Information Processing Systems, Vancouver, BC, Canada, 6–12 December 2020.

  • 16.

    Zhang, R.; Li, H.; Wen, R.; et al. Instruction Backdoor Attacks Against Customized LLMs. arXiv 2024, arXiv:2402.09179.

  • 17.

    Liu, X.; Song, Q.; Zhou, Q.; et al. Focusing on Language: Revealing and Exploiting Language Attention Heads in Multilingual Large Language Models. arXiv 2025, arXiv:2511.07498.

  • 18.

    Organisation for Economic Co-Operation and Development. The Digital Transformation of SMEs; Technical Report; OECD: Paris, France, 2021.

  • 19.

    Deng, S.; Zhao, H.; Huang, B.; et al. Cloud-Native Computing: A Survey From the Perspective of Services. Proc. IEEE 2024, 112, 12–46.

  • 20.

    Cloud Native Computing Foundation (CNCF). Kubernetes: Production-Grade Container Orchestration. 2025. Available online: https://v1-33.docs.kubernetes.io/ (accessed on 1 December 2025).

  • 21.

    Rancher Labs. k3s: Lightweight Kubernetes. 2024. Available online: https://docs.k3s.io/ (accessed on 1 December 2025).

  • 22.

    Australian Government. Privacy Act 1988. Office of the Australian Information Commissioner (OAIC). 1988. Available online: https://www.legislation.gov.au/C2004A03712/latest/text (accessed on 1 January 2026).

  • 23.

    Australian Government. Australian Privacy Principles. Office of the Australian Information Commissioner (OAIC). Available online: https://www.oaic.gov.au/privacy/australian-privacy-principles (accessed on 1 January 2026).

  • 24.

    Wu, Q.; Bansal, G.; Zhang, J.; et al. AutoGen: Enabling Next-Gen LLM Applications via Multi-Agent Conversation. arXiv 2023, arXiv:2308.08155.

  • 25.

    Karpas, E.; Abend, O.; Belinkov, Y.; et al. MRKL Systems: A modular, neuro-symbolic architecture that combines large language models, external knowledge sources and discrete reasoning. arXiv 2022, arXiv:2205.00445.

  • 26.

    Perez, F.; Ribeiro, I. Ignore Previous Prompt: Attack Techniques For Language Models. arXiv 2022, arXiv:2211.09527.

  • 27.

    Greshake, K.; Abdelnabi, S.; Mishra, S.; et al. Not what you’ve signed up for: Compromising Real-World LLM-Integrated Applications with Indirect Prompt Injection. arXiv 2023, arXiv:2302.12173.

  • 28.

    Xia, Z.; Sun, H.; Wang, J.; et al. The Threat of PROMPTS in Large Language Models: A System and User Prompt Perspective. In Proceedings of the Findings of the Association for Computational Linguistics (ACL 2025), Vienna, Austria, 27 July–1 August 2025; pp. 12994–13035.

  • 29.

    Li, X.; Wang, S.; Zeng, S.; et al. A survey on LLM-based multi-agent systems: workflow, infrastructure, and challenges. Vicinagearth 2024, 1, 9. https://doi.org/10.1007/s44336-024-00009-2.

  • 30.

    Ji, Z.; Lee, N.; Frieske, R.; et al. Survey of Hallucination in Natural Language Generation. ACM Comput. Surv. 2023, 55, 248. https://doi.org/10.1145/3571730.

  • 31.

    Learn Prompting. Instruction Defense. 2023. Available online: https://learnprompting.org/docs/prompthacking/defensivemeasures/instruction (accessed on 16 December 2025).

  • 32.

    Willison, S. Delimiters Won’t Save You from Prompt Injection. 2023. Available online: https://simonwillison.net/2023/May/11/delimiters-wont-save-you/ (accessed on 16 December 2025).

  • 33.

    deepset. Deepset/Prompt-Injections. Hugging Face Dataset. 2024. Available online: https://huggingface.co/datasets/deepset/prompt-injections (accessed on 1 December 2025).

  • 34.

    Santana, O. Prompt Injection Attack Detection Multilingual. 2024. Available online: https://huggingface.co/datasets/Octavio-Santana/prompt-injection-attack-detection-multilingual (accessed on 1 December 2025).

Share this article:
How to Cite
Xie, J.; Wang, Q.; Li, B.; Xu, Z.; Han, F. Trustworthy Deployment of LLM-Based RAG Systems for Small Businesses: A Security and Confidence-Aware Framework . Pragmatic Cybersecurity 2026, 1 (2), 8. https://doi.org/10.53941/pc.2026.100008.
RIS
BibTex
Copyright & License
article copyright Image
Copyright (c) 2026 by the authors.