提出可落地的隐私防护方案,显著降低大模型代理的隐私泄露风险。
Privacy in Action: Towards Realistic Privacy Mitigation and Evaluation for LLM-Powered Agents
- 基于上下文完整性设计通用隐私防护机制,不依赖特定模型。
- 在DeepSeek-R1和GPT-4o上将隐私泄露率从36.08%降至7.30%。
- 构建动态测试环境,揭示真实场景下更高的隐私风险,适合开发者部署。
LLM代理在处理敏感通信时自主性增强,由模型上下文协议(MCP)和代理间(A2A)框架推动,带来紧迫的隐私挑战。现有研究显示,大模型在隐私问答性能与代理行为之间存在显著差距,而现有基准仍局限于静态、简化的场景。我们提出PrivacyChecker,一种与模型无关、基于上下文完整性的缓解方法,在DeepSeek-R1上将隐私泄露率从36.08%降至7.30%,在GPT-4o上从33.06%降至8.32%,同时保持任务帮助性。我们还引入PrivacyLens-Live,将静态基准转化为动态MCP与A2A环境,揭示实际应用中更高的隐私风险。该模块化缓解方案可通过三种部署策略无缝集成至代理协议,为新兴代理生态提供实用隐私保护。数据与代码将公开于https://aka.ms/privacy_in_action。
原文摘要 · Abstract (English)
The increasing autonomy of LLM agents in handling sensitive communications, accelerated by Model Context Protocol (MCP) and Agent-to-Agent (A2A) frameworks, creates urgent privacy challenges. While recent work reveals significant gaps between LLMs' privacy Q&A performance and their agent behavior, existing benchmarks remain limited to static, simplified scenarios. We present PrivacyChecker, a model-agnostic, contextual integrity based mitigation approach that effectively reduces privacy leakage from 36.08% to 7.30% on DeepSeek-R1 and from 33.06% to 8.32% on GPT-4o, all while preserving task helpfulness. We also introduce PrivacyLens-Live, transforming static benchmarks into dynamic MCP and A2A environments that reveal substantially higher privacy risks in practical. Our modular mitigation approach integrates seamlessly into agent protocols through three deployment strategies, providing practical privacy protection for the emerging agentic ecosystem. Our data and code will be made available at https://aka.ms/privacy_in_action.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。