June 2026Unreviewed
An Evaluation of Data Leakage Risks in Tool-Using LLM Agents in Realistic Scenarios
Hankyul Baek, Jaewon Noh, Sang Seo, Yongsu Kim, Gabriel Waikin Loh Matienzo, Young Il Kim, Ee Wei Seah, Akriti Vij
Abstract
AI agents are increasingly being adopted in enterprise and personal settings with access to emails, databases, documents, and other tools where they can read, update, and disseminate sensitive information. Much of prior research on data leakage risks in agents has focused on adversarial data exfiltration through prompt injections and jailbreaks. However, sensitive information may also be exposed during non-adversarial use, creating leakage risks even when users issue benign requests. We report a
Categories
Framework mappings
OWASP Top 10 for LLM Applications
- LLM01Prompt Injection
- LLM02Sensitive Information Disclosure
MITRE ATLAS
- AML.T0024.000Infer Training Data Membership
- AML.T0051LLM Prompt Injection
- AML.T0054LLM Jailbreak
Suggested from the entry's categories.
Cite
@misc{baek2026evaluation,
title = {{An Evaluation of Data Leakage Risks in Tool-Using LLM Agents in Realistic Scenarios}},
author = {Hankyul Baek and Jaewon Noh and Sang Seo and Yongsu Kim and Gabriel Waikin Loh Matienzo and Young Il Kim and Ee Wei Seah and Akriti Vij},
year = {2026},
month = jun,
eprint = {2606.17114},
archivePrefix = {arXiv},
url = {https://arxiv.org/abs/2606.17114}
}