The paper argues that privacy in personalized AI should be viewed as a system-level issue rather than just a model-level one. It identifies four interconnected privacy‑risk channels in personalized AI and proposes four system‑level requirements—interaction trajectories, internal information flows, indirect leakage, and the privacy‑utility trade‑off—for evaluating privacy. The authors call for these requirements to be systematically incorporated into privacy audits of personalized AI systems.
By Guillaume Salha-Galvan, Jiaying Xu
arXiv:2609.35937v1 Announce Type: cross
Abstract: While prior work has documented privacy failures in LLM agents, it remains unclear how the presentation of privacy guidance influences their choice o...
By Lucas Biechy, C\'edric Eichler, H\'eber H. Arcolezi, Nicolas Anciaux
arXiv:2606. 09844v1 Announce Type: cross Abstract: Large Language Models (LLMs) alter their privacy behavior based on the perceived identity of their interlocutor.
By Faouzi El Yagoubi, Godwin Badu-Marfo, Ranwa Al Mallah
arXiv:2607. 13718v1 Announce Type: cross Abstract: As AI agents gain prevalance, users are increasingly exposed to the risks such systems entail.
By Alexandra E. Michael, Franziska Roesner
arXiv:2607. 05363v1 Announce Type: new Abstract: Personal agents are becoming persistent user-owned intermediaries: they remember preferences, filter platform-mediated information, use tools, and negotiate with services.
By Dylan Zongmin Liu
The paper introduces the concept of personalized privacy for large language models, allowing user‑specific disclosure preferences to guide information sharing. It presents P3Bench, a benchmark that extends contextual privacy policies with personalized rules, and shows that existing prompt‑based methods often ignore these policies. To improve compliance, the authors propose “Repair”, an inference‑time attention head intervention that aligns model responses with user‑specific privacy rules.
By Junseok Kim, Nakyeong Yang, Kyomin Jung
arXiv:2607. 01510v1 Announce Type: new Abstract: AI agents that autonomously execute tool calls on a user's behalf raise pressing questions about permission management: what role could users play, and what role should they play?
By Natalie Grace Brigham, Eugene Bagdasarian, Tadayoshi Kohno, Franziska Roesner
The study investigates how users perceive the helpfulness and privacy-preservation of large language model (LLM) responses in privacy-sensitive scenarios. Using 94 participants and 90 PrivacyLens scenarios, researchers found that users’ evaluations of identical LLM outputs varied widely, whereas five proxy LLM judges showed high agreement but low correlation with user judgments. The results suggest that proxy LLMs cannot reliably estimate users’ diverse perceptions of utility and privacy, highlighting the need for more user-centered evaluation methods.
By Xiaoyuan Wu, Roshni Kaushik, Wenkai Li, Lujo Bauer, Koichi Onoue
arXiv:2606. 26627v1 Announce Type: cross Abstract: Large language model agents increasingly query databases, search document collections, call external APIs, remember past interactions, and act on a user's behalf.
By Nada Lahjouji, Ashwin Gerard Colaco
arXiv:2607. 18257v1 Announce Type: cross Abstract: When AI agents shift from answering questions to taking actions, users face a new problem: deciding what to delegate, to a system whose action space they cannot fully anticipate.
By Shiva Pochampally, Shengwei An, Yan Chen
arXiv:2606. 00152v1 Announce Type: cross Abstract: LLM-based agents are rapidly advancing, autonomously invoking external tools to complete multi-step tasks for users.
By Mingxuan Zhang, Jiahui Han, Dadi Guo, Songze Li, Guanchu Wang, Na Zou, Dongrui Liu, Xia Hu
arXiv:2601. 14660v2 Announce Type: replace-cross Abstract: Agentic Large Language Models (LLMs) are models able to reason, plan, and execute tools over unstructured data.
By Saswat Das, Ferdinando Fioretto