PrivacyPeek: Uncovering Widespread Privacy Over-Acquisition in LLM Agents
Mingxuan Zhang · hf · 2026-08-10
LLM-based agents often acquire more sensitive information than necessary when autonomously invoking tools. While existing privacy benchmarks audit agent outputs, they overlook the acquisition stage where data first enters the context. To address this, researchers introduced PrivacyPeek, a benchmark evaluating acquisition-stage privacy leakage.
Featuring 1,182 cases across 7 behaviors and 16 domains, the benchmark tests agents via acquisition inspection and probe elicitation. Experiments on 10 agents reveal that unnecessary acquisition of sensitive information is widespread. Notably, task-completion capability correlates with leakage, and prompt-level defenses mitigate only a small fraction of the risk.
More from coding & agent
- Developer Teases Upcoming Open-Source Release of App with Persistent Terminal — zhengyiluo · 2026-08-10
- AI Coding Agent Blows Through $19 Instantly, Highlighting Cost Control Risks — teortaxesTex · 2026-08-10
- Ex-OpenAI Advisor: Gradual Milestones Are Normalizing AI Self-Improvement — Miles_Brundage · 2026-08-10
- Awesome Agents: A Curated GitHub Directory of Open-Source AI Agent Tools — tom_doerr · 2026-08-10
- OpenSDL: An Open-Source Python Framework for Autonomous Laboratories — w1kke · 2026-08-10
- AI Coding Workflow: When to Review Generated Code vs. Vibe Coding — bendee983 · 2026-08-10