LLM Attack: Anonymized Users Identified via Text
OwainEvans_UK · x · 2026-08-25
This arXiv paper demonstrates that LLMs can perform at-scale deanonymization attacks.
Core Findings:
- An agent with full internet access can re-identify Hacker News users and Anthropic Interviewer participants with high precision using only pseudonymous profiles and conversations.
- The method matches what would take hours for a dedicated human investigator.
Attack Pipeline:
- Extract Features: Extract identity-relevant features from unstructured text.
- Search Candidates: Find potential matches via semantic embeddings.
- Reason & Verify: Reason over top candidates to verify matches and reduce false positives.
Datasets:
- Hacker News <-> LinkedIn: Uses cross-platform references.
- Reddit Movie Communities: Matches users across different subreddits.
- Time Split: Splits a single user's Reddit history to create two profiles for matching.
Results: LLM-based methods substantially outperform classical baselines, achieving up to 68% recall at 90% precision.
Related event: AI Agents Excel at Fact-Checking but Enable De-anonymization(2 posts)→
More from Safety
- MKBHD Awards Beni Camera Robot 10/10, Sparking Surveillance Concerns — Competitive_Travel16 · 2026-08-25
- Court expert used ChatGPT to write report concluding 3M had 0% fault in explosion — ZeroStateReflex · 2026-08-25
- Viewpoint: More OpenAI Researchers Shift Stance on Alignment Risks — davidmanheim · 2026-08-25
- Richard Ngo previews part 2 of his alignment retrospective — RichardMCNgo · 2026-08-25
- UK, Ukraine sign AI defense partnership sharing 5M battlefield images — Polymarket · 2026-08-25
- CISA warns of AI-generated threats to Siemens PLCs — dhadfieldmenell · 2026-08-25