🛰️ Daily AI Frontier
‹ back to 2026-09-21

CIPL: A Channel-Aware Framework for Recoverable Privacy Leakage in LLM Agents

arXiv cs.CR LLM Agents Tao Huang, Guosen Wu, Guolong Zheng, Jiayang Meng, Chen Hou, Xu Yang, Xuechao Yang, Feng Xia 2026-09-18
Representative image for CIPL: A Channel-Aware Framework for Recoverable Privacy Leakage in LLM Agents

TL;DR - CIPL is a channel-aware framework for measuring sensitive information that attackers can recover from black-box LLM agents, rather than merely detecting internal exposure. It enables consistent comparisons across memory-, retrieval-, tool-, and live-agent pipelines.

  • Models leakage through source, selection, assembly, execution, observation, and extraction stages under a shared protocol.
  • Memory leakage was nearly saturated, while retrieval-mediated leakage was often partial.
  • Tool-mediated and live-agent leakage varied with observation surface, prompt-channel alignment, retrieval depth, and provider behavior.
  • Semantic auditing identified useful disclosures missed by canonical exact-match metrics.

view merged work →