AI Briefing
KO

Privacy Threats in AI Agents, MosaicLeaks

·2026.06.19 03:13

Key point

This work identifies the 'Mosaic Effect,' where external queries by AI research agents leak sensitive information, and proposes a solution.

Details

It has been confirmed that when an AI research agent references personal documents and uses external tools (such as web search), individual queries may appear harmless, but combining them can reveal sensitive information — a phenomenon called the 'Mosaic Effect.'

To measure this, the researchers proposed a new task called MosaicLeaks. This task analyzes the web query logs an agent performs to answer questions involving sensitive information, measuring leakage at three levels:

  • Intent leakage: Identifying what the agent is trying to investigate
  • Answer leakage: Deriving the answer to a sensitive question from the query logs alone
  • Full-information leakage: Discovering sensitive facts from the combination of query logs alone, without the question

Experimental results showed that existing models tended to leak more information as they were optimized for performance. In response, the researchers proposed PA-DR (Privacy-Aware Deep Research), a reinforcement learning (RL) training method, achieving a task success rate of 58.7% while significantly reducing full-information leakage from 34.0% to 9.9%.

This summary was generated automatically by AI. Check the original for the author's claims and context. Copyright belongs to the original author.

Our guide explains how the AI works. Report summary errors, attribution issues, or removal requests via Contact.