Agent Tools Orchestration Leaks More: Dataset, Benchmark, and Mitigation
cs.CR, cs.AI, cs.CL
Submitted: 2025-12-18
Updated: 2026-09-02
Comments: Accepted to EMNLP 2026 Findings. 20 pages, 2 figures. Code and data: https://github.com/1Ponder/TOP-R
Code: https://github.com/1Ponder/TOP-R
License: http://arxiv.org/licenses/nonexclusive-distrib/1.0/
Terminology
Sources
- CI-Work: Benchmarking Contextual Integrity in Enterprise LLM Agents
- MAGPIE: A benchmark for Multi-AGent contextual PrIvacy Evaluation
- CI-Bench: Benchmarking Contextual Integrity of AI Assistants on Synthetic Data
- Can LLMs Keep a Secret? Testing Privacy Implications of Language Models via Contextual Integrity Theory
- Safe RLHF: Safe Reinforcement Learning from Human Feedback
- Position: Privacy Is Not Just Memorization!
- CIMemories: A Compositional Benchmark for Contextual Integrity of Persistent Memory in LLMs
- The Sum Leaks More Than Its Parts: Compositional Privacy Risks and Mitigations in Multi-Agent Collaboration
- Privacy in Action: Towards Realistic Privacy Mitigation and Evaluation for LLM-Powered Agents
- The Rise and Potential of Large Language Model Based Agents: A Survey
- ToolLLM: Facilitating Large Language Models to Master 16000+ Real-world APIs
- SPILLage: Agentic Oversharing on the Web
- AgentLeak: A Benchmark for Internal-Channel Privacy Leakage in Multi-Agent LLM Systems
- Identifying the Risks of LM Agents with an LM-Emulated Sandbox
- InjecAgent: Benchmarking Indirect Prompt Injections in Tool-Integrated Large Language Model Agents
- Evaluating Language Model Reasoning about Confidential Information
- Searching for Privacy Risks in LLM Agents via Simulation
- AgentDAM: Privacy Leakage Evaluation for Autonomous Web Agents
- Beyond Memorization: Violating Privacy Via Inference with Large Language Models
Related papers
- SoK: AI-Augmented Binary Reversing
- Relaxed Sender Anonymity for CBDC Interbank Settlement: A Zero-Knowledge Approach on Permissioned EVM
- Calibration-Family Overfit: Why Trusted Sabotage Monitors Don't Transfer Across Lineages
- Efficient Fuzzy PSI under One-Sided Assumptions
- Sealing the Audit-Runtime Gap for LLM Skills
- Token Composition: A Graph Based on EVM Logs