arXiv:2602.17483cs.HCcs.AI2026-02

测试大模型如何关联用户姓名,发现其能高精度生成个人隐私信息。

What Do LLMs Associate with Your Name? A Human-Centered Black-Box Audit of Personal Data

  • 设计隐私审计工具LMP2,通过用户研究优化,保护隐私同时检测模型关联
  • GPT-4o对普通人可准确生成11项个人信息,如性别、发色等,准确率超60%
  • 72%用户希望控制模型对自身姓名的关联,引发数据隐私边界讨论

大型语言模型(LLMs)在预训练和用户交互中暴露于个人数据(PD)。已有研究显示个人数据可能重现,但用户难以了解模型对自身身份的关联强度。本研究审计了八种LLM(3个开源,5个API模型,含GPT-4o),提出人本中心的隐私保护审计工具LMP2,经两次前期研究(N=20)迭代优化,并开展两项研究:一是收集欧盟居民对模型生成个人数据的直觉(N1=155),二是评估其对工具输出的反应(N2=303)。实证表明,模型对知名人物会自信生成多个个人数据类别。对普通用户而言,GPT-4o能以60%以上准确率生成11项特征(如性别、发色、语言)。最后,72%参与者希望控制模型对自身姓名的关联,促使重新思考何为个人数据,以及数据隐私权是否应扩展至大模型。

原文摘要 · Abstract (English)

Large language models (LLMs), and conversational agents based on them, are exposed to personal data (PD) during pre-training and during user interactions. Prior work shows that PD can resurface, yet users lack insight into how strongly models associate specific information to their identity. We audit PD across eight LLMs (3 open-source; 5 API-based, including GPT-4o), introduce LMP2 (Language Model Privacy Probe), a human-centered, privacy-preserving audit tool refined through two formative studies (N=20), and run two studies with EU residents to capture (i) intuitions about LLM-generated PD (N1=155) and (ii) reactions to tool output (N2=303). We show empirically that models confidently generate multiple PD categories for well-known individuals. For everyday users, GPT-4o generates 11 features with 60% or more accuracy (e.g., gender, hair color, languages). Finally, 72% of participants sought control over model-generated associations with their name, raising questions about what counts as PD and whether data privacy rights should extend to LLMs.

大模型隐私个人数据审计工具用户研究

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。