ASLEval: Measuring Privacy Exposure Displacement in LLM Agent Sessions

๐Ÿ“… 2026-09-16
๐Ÿ“ˆ Citations: 0
โœจ Influential: 0
๐Ÿ“„ PDF
๐Ÿค– AI Summary
ๆœฌๆ–‡ๆๅ‡บASLEvalๆก†ๆžถ๏ผŒ้€š่ฟ‡้ข„ๆณจๅ†Œ้š่—็›ฎๆ ‡้›†ใ€ๆต‹้‡ๆ‰€ๆœ‰ๅฏ่งๅ‡บๅฃๅนถไฟ็•™ๅ†…้ƒจ็—•่ฟนๆฅ่งฃๅ†ณๅคšๆญฅ้ชคไผš่ฏไธญ้š็งๆšด้œฒ้”™ไฝ็š„้—ฎ้ข˜ใ€‚
๐Ÿ“ Abstract
Privacy evaluations of tool-using LLM agents often inspect a designated action, final response, or attacker report. These local proxies can miss unauthorized exposure elsewhere in a multi-step session and lack common ground truth across outlets, reports, and tool paths. We introduce privacy exposure displacement, the mismatch between a local evaluation proxy and target-grounded session exposure, and ASLEval, an authorization-aware framework that pre-registers a hidden target set, measures all declared visible exits, and reserves internal traces for diagnosis. Across multiple enterprise-style environments and independently implemented runtimes, we observe three recurring patterns. An expected-outlet-only view misses 46.9% of exposure recovered by the visible-exit union; attacker self-reports combine omissions with high false discovery; and schema-aligned internal evidence usually precedes visible exposure at the request/probe level. Reducing model-visible returns changes this path but can eliminate normal-task success. Independent human review supports the adjudication pipeline while identifying harder console and candidate cases. These findings motivate benchmarks that declare the complete visible boundary, ground claims in pre-specified targets and authorization, and report privacy together with task utility.
Problem

Research questions and friction points this paper is trying to address.

privacy evaluation
LLM agent
exposure displacement
multi-step session
Innovation

Methods, ideas, or system contributions that make the work stand out.

privacy exposure displacement
ASLEval framework
multi-step session
G
Guosen Wu
School of Computer and Big Data, Minjiang University, Fuzhou, China
H
Huizhen Huang
School of Computer and Big Data, Minjiang University, Fuzhou, China
G
Guoxiong Long
School of Computer and Big Data, Minjiang University, Fuzhou, China
Tao Huang
Tao Huang
Information School of Renmin University of China
differential privacystatistical machine learningstatistical inference
Chen Hou
Chen Hou
Associate Professor of Biological Sciences, Missouri University of Science and Technology
Ecophysiologyaginglife historyenergetics