用普通AI工具可轻松还原科研访谈中匿名者身份,揭示数据公开风险。
Agentic LLMs as Powerful Deanonymizers: Re-identification of Participants in the Anthropic Interviewer Dataset
- 利用具备网络搜索能力的AI代理,通过自然语言提示完成跨文档匹配
- 在24个科学家访谈中成功关联6篇论文并定位作者,实现身份复原
- 适合关注隐私保护与数据安全的研究者,警示开放高质量访谈数据的风险
2025年12月4日,Anthropic发布了用于大规模开展定性访谈的AI工具Anthropic Interviewer,同时公开了包含1,250名专业人士(含125名科学家)访谈的公共数据集,内容涉及其使用AI进行科研的情况。本文聚焦科学家子集,发现具备网络搜索和智能体功能的通用大模型仅需少量自然语言提示,即可通过网页检索、信息交叉验证,将24个访谈中的6个成功关联至具体科研论文,进而恢复作者信息,部分案例可唯一识别受访者。本研究揭示:现代基于LLM的智能体使再识别攻击变得简单且低门槛;现有防护机制可通过分解为看似无害的任务绕过。文章概述攻击流程,讨论在大模型时代发布丰富定性数据的伦理与安全影响,并提出缓解建议与未解问题。相关发现已通报Anthropic。
原文摘要 · Abstract (English)
On December 4, 2025, Anthropic released Anthropic Interviewer, an AI tool for running qualitative interviews at scale, along with a public dataset of 1,250 interviews with professionals, including 125 scientists, about their use of AI for research. Focusing on the scientist subset, I show that widely available LLMs with web search and agentic capabilities can link six out of twenty-four interviews to specific scientific works, recovering associated authors and, in some cases, uniquely identifying the interviewees. My contribution is to show that modern LLM-based agents make such re-identification attacks easy and low-effort: off-the-shelf tools can, with a few natural-language prompts, search the web, cross-reference details, and propose likely matches, effectively lowering the technical barrier. Existing safeguards can be bypassed by breaking down the re-identification into benign tasks. I outline the attack at a high level, discuss implications for releasing rich qualitative data in the age of LLM agents, and propose mitigation recommendations and open problems. I have notified Anthropic of my findings.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。