arXiv:2603.05520cs.MAcs.CR2026-03被引 7

提出系统级隐私保护方法,防止多智能体大模型串行推理泄露敏感信息。

Information-Theoretic Privacy Control for Sequential Multi-Agent LLM Systems

  • 用互信息建模串行代理间的隐私泄露,推导出泄漏放大理论边界。
  • 设计隐私正则化训练框架,直接约束代理输出与敏感变量的信息流。
  • 在多个数据集上验证了隐私-效用平衡的稳定性,适合高敏感场景应用。

序列式多智能体大语言模型系统正被广泛应用于医疗、金融和企业决策等敏感领域,多个专业代理协同处理单一用户请求。尽管各代理满足本地隐私约束,但通过串行组合与中间表示仍可能泄露敏感信息。本文研究串行代理流水线中的组合隐私泄露问题,利用互信息形式化泄露,并推导出在串行执行下局部引入的泄露如何被放大的理论边界。基于此分析,我们提出一种隐私正则化训练框架,直接约束代理输出与代理本地敏感变量之间的信息流。在三个基准数据集上的不同深度串行代理流水线中评估该方法,结果显示优化过程稳定,且隐私-效用权衡一致可解释。结果表明,代理式大模型系统的隐私不能仅靠局部约束保证,必须在训练与部署阶段作为系统级属性加以管理。

原文摘要 · Abstract (English)

Sequential multi-agent large language model (LLM) systems are increasingly deployed in sensitive domains such as healthcare, finance, and enterprise decision-making, where multiple specialized agents collaboratively process a single user request. Although individual agents may satisfy local privacy constraints, sensitive information can still be inferred through sequential composition and intermediate representations. In this work, we study \emph{compositional privacy leakage} in sequential LLM agent pipelines. We formalize leakage using mutual information and derive a theoretical bound that characterizes how locally introduced leakage can amplify across agents under sequential execution. Motivated by this analysis, we propose a privacy-regularized training framework that directly constrains information flow between agent outputs and agent-local sensitive variables. We evaluate our approach across sequential agent pipelines of varying depth on three benchmark datasets, demonstrating stable optimization dynamics and consistent, interpretable privacy-utility trade-offs. Our results show that privacy in agentic LLM systems cannot be guaranteed by local constraints alone and must instead be treated as a system-level property during both training and deployment.

隐私保护多智能体大模型

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。