arXiv:2604.01487cs.AIcs.SI2026-04被引 5

首个评估人中心智能体社交网络隐私风险的基准,揭示协作中信息泄露难题。

AgentSocialBench: Evaluating Privacy Risks in Human-Centered Agentic Social Networks

  • 构建七类真实场景的隐私评测基准,含多用户跨域交互
  • 发现跨域协作导致持续信息泄露,即使明确要求保密也难避免
  • 提出'抽象悖论':教智能体隐藏敏感信息反而使其更易暴露

随着OpenClaw等个性化、持久化大模型智能体框架的发展,以多个协作智能体服务单个用户的跨领域人中心智能体社交网络正成为现实。此类系统带来全新隐私挑战:智能体需在领域间协调、代为沟通并与其他用户智能体交互,同时保护敏感个人信息。尽管已有研究关注多智能体协作与隐私保护,但人中心智能体社交网络中的动态机制与隐私风险仍待探索。为此,我们提出AgentSocialBench,首个系统评估该场景下隐私风险的基准,涵盖七类场景,包含二元与多方互动,基于带层级敏感度标签的真实用户画像和有向社交图。实验表明,智能体社交网络中的隐私保护远比单智能体设置困难:(1) 跨域与跨用户协作造成持续泄露压力,即便明确指令保护信息亦无法避免;(2) 教导智能体抽象敏感信息的隐私指令反而引发其更频繁讨论敏感内容(称作‘抽象悖论’)。这些发现表明,当前大模型智能体在人中心社交网络中缺乏稳健隐私保护机制,仅靠提示工程不足以支撑真实部署安全,亟需新方法。

原文摘要 · Abstract (English)

With the rise of personalized, persistent LLM agent frameworks such as OpenClaw, human-centered agentic social networks in which teams of collaborative AI agents serve individual users in a social network across multiple domains are becoming a reality. This setting creates novel privacy challenges: agents must coordinate across domain boundaries, mediate between humans, and interact with other users' agents, all while protecting sensitive personal information. While prior work has evaluated multi-agent coordination and privacy preservation, the dynamics and privacy risks of human-centered agentic social networks remain unexplored. To this end, we introduce AgentSocialBench, the first benchmark to systematically evaluate privacy risk in this setting, comprising scenarios across seven categories spanning dyadic and multi-party interactions, grounded in realistic user profiles with hierarchical sensitivity labels and directed social graphs. Our experiments reveal that privacy in agentic social networks is fundamentally harder than in single-agent settings: (1) cross-domain and cross-user coordination creates persistent leakage pressure even when agents are explicitly instructed to protect information, (2) privacy instructions that teach agents how to abstract sensitive information paradoxically cause them to discuss it more (we call it abstraction paradox). These findings underscore that current LLM agents lack robust mechanisms for privacy preservation in human-centered agentic social networks, and that new approaches beyond prompt engineering are needed to make agent-mediated social coordination safe for real-world deployment.

智能体系统隐私风险多智能体社会网络

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。