分析用户向大模型询问安全隐私问题的真实对话,发现商用模型回应更好但有时自相矛盾。
Security and Privacy Prompts in the Wild: What Users Ask LLMs and How LLMs Respond

- 从320万条真实对话中提取1.47万条安全隐私提问,分类为九类主题
- 商用模型(GPT 5.5)在98%提问上给出可用回答,开源模型(Llama 4)仅47%
- 即使平均质量高,商用模型在多次运行中仍可能输出矛盾建议
大型语言模型(LLMs)被广泛用于满足用户的各类信息需求,如天气查询、教育答疑和法律咨询。然而,关于数字安全与隐私(S&P)领域的研究仍严重不足——用户常向模型求助账户保护或防网络攻击方法,但此前缺乏对真实用户提问的系统收集与分析。本研究基于野生成数据集WildChat(含320万条用户-模型对话),识别出14,727条安全隐私相关提示,并将其划分为九个类别。从中抽样450条进行主题分析,另精选270条建议寻求型提问,通过十次重复测试评估模型响应质量与一致性。结果表明:商业模型(如GPT 5.5)在98%的提示中提供“足够好”的回答,显著优于开源模型(如Llama 4,仅47%);但在高均质性表现下,部分商业模型在多次运行中仍出现自相矛盾的回答,存在误导风险。
原文摘要 · Abstract (English)
Large language models (LLMs) are widely used to fulfill users' information needs; users ask LLMs about the weather, pose educational questions, and consult them for legal assistance. One particularly understudied area is digital security and privacy (S&P), where users may seek LLMs' help on how to secure their online accounts or protect their computers from cyber attacks. To the best of our knowledge, no prior study has collected or analyzed the S&P questions users ask LLMs; prior research on LLM response quality relied on expert-authored S&P misconceptions or FAQs rather than user queries. Drawing from WildChat, a dataset of 3.2M user-LLM conversations collected in the wild, our study identifies 14,727 S&P prompts and categorizes them into nine categories covering a wide range of S&P topics. From the S&P prompts, we sampled 450 and performed a thematic analysis to characterize the S&P questions users ask LLMs. Separate from the thematic analysis, we curated 270 advice-seeking S&P prompts, where users ask for recommendations, guidance, or specific S&P information. We measured LLM response quality and consistency when posing the prompt to LLMs 10 times. We found that commercial LLMs outperform open-weight models (GPT 5.5 provided "good enough" responses on 98% of prompts; Llama 4 on 47%). However, among prompts that received high-quality responses on average, commercial models sometimes produce contradictory responses across runs, risking confusing or misleading users.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。