June 2026Unreviewed
Agents That Know Too Much: A Data-Centric Survey of Privacy in LLM Agents
Nada Lahjouji, Ashwin Gerard Colaco
Abstract
Large language model agents increasingly query databases, search document collections, call external APIs, remember past interactions, and act on a user's behalf. As they move from answering questions to operating over sensitive data, privacy becomes harder to enforce. An agent touches many data sources, runs multi-step workflows, keeps state across sessions, and acts with delegated permissions. Sensitive information can therefore leak not only through its final answer but through the queries it
Categories
Framework mappings
OWASP Top 10 for LLM Applications
- LLM02Sensitive Information Disclosure
MITRE ATLAS
- AML.T0024.000Infer Training Data Membership
Suggested from the entry's categories.
Cite
@misc{lahjouji2026agents,
title = {{Agents That Know Too Much: A Data-Centric Survey of Privacy in LLM Agents}},
author = {Nada Lahjouji and Ashwin Gerard Colaco},
year = {2026},
month = jun,
eprint = {2606.26627},
archivePrefix = {arXiv},
url = {https://arxiv.org/abs/2606.26627}
}