arXiv:2603.18382cs.AI2026-03中稿 · ICML被引 3

大模型代理能从零碎线索推断真实身份,威胁隐私安全。

From Weak Cues to Real Identities: Evaluating Inference-Driven De-Anonymization in LLM Agents

  • 利用零散非敏感线索与公开信息联动推断身份
  • 在Netflix数据集中身份重建率达79.2%(基线56.0%)
  • 适用于评估智能体系统的隐私风险,尤其关注推理能力

去匿名化常被认为在移除显式标识后即保障隐私,因以往重识别需专业技能、定制算法和人工验证。我们发现基于大模型的智能体削弱了这一屏障:通过结合分散的、单个不具识别性的线索与公开证据,可重构真实身份,甚至在常规任务中实现。我们在三种场景下评估该风险——经典关联事件、受控基准(InferLink),其变量包括指纹类型、任务表述与攻击者知识水平,以及开放的人机交互记录。在Netflix Prize去匿名化设置中最稀疏的情形下,智能体成功重建79.2%的身份,高于传统匹配基线的56.0%;在InferLink中,即使无明确重识别请求,也能完成关联,一旦提出请求则成功率更高。在匿名化的人机交互记录中,智能体通过整合上下文线索与公开信息,进一步将匿名身份定位至具体个人。这些结果表明,对智能体系统的隐私评估应不仅关注信息访问或披露,还应衡量其推断身份的能力。

原文摘要 · Abstract (English)

Anonymization is often assumed to protect privacy once explicit identifiers are removed, because re-identification has historically required specialized expertise, tailored algorithms, and manual corroboration. We show that LLM-based agents weaken this barrier: by combining scattered, individually non-identifying cues with public evidence, they reconstruct real-world identities, sometimes even during benign tasks. We evaluate this risk across three settings -- classical linkage incidents, a controlled benchmark (\emph{InferLink}) that varies fingerprint type, task framing, and attacker knowledge, and open-ended human--AI interaction traces. In the sparsest regime of the Netflix Prize deanonymization setting, agents reconstruct 79.2\% of identities, against 56.0\% for a classical matching baseline; on \emph{InferLink}, they link individuals even without an explicit re-identification request, and more often once one is given. In redacted human--AI interaction traces, agents further resolve anonymized profiles to specific individuals by corroborating contextual cues with public evidence. These findings suggest that privacy evaluations for agentic systems should measure not only what information is accessed or disclosed, but also what identities can be inferred.

隐私安全大模型风险身份推断

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。