about
Companies should be liable for the serious privacy concerns of LLMs (arxiv.org)
9 points by mrharoon on Jun 23, 2025 | hide | past | pdf | discuss on HN

In plain words: AI agents that think step by step before answering often write private user details into their hidden thinking, where attackers can pull them out. Asking them to think longer made their final answers more careful but their thinking leaked more.

Abstract · Leaky Thoughts: Large Reasoning Models Are Not Private Thinkers

We study privacy leakage in the reasoning traces of large reasoning models used as personal agents. Unlike final outputs, reasoning traces are often assumed to be internal and safe. We challenge this assumption by showing that reasoning traces frequently contain sensitive user data, which can be extracted via prompt injections or accidentally leak into outputs. Through probing and agentic evaluations, we demonstrate that test-time compute approaches, particularly increased reasoning steps, amplify such leakage. While increasing the budget of those test-time compute approaches makes models more cautious in their final answers, it also leads them to reason more verbosely and leak more in their own thinking. This reveals a core tension: reasoning improves utility but enlarges the privacy attack surface. We argue that safety efforts must extend to the model's internal thinking, not just its outputs.

Tommaso Green, Martin Gubri, Haritz Puerto, Sangdoo Yun, Seong Joon Oh
arXiv:2506.15674 · cs.CL, cs.AI, cs.CR · submitted Jun 18, 2025 · updated Oct 1, 2025
abstract · pdf · html · Accepted to EMNLP 2025 (Main)

add comment on HN