Skip to content
Search
paperAugust 2026Unreviewed

Context Inference Attacks Without Jailbreaks

Prince Jha, Samuele Poppi, Nils Lukas

Abstract

Agentic AI systems are increasingly deployed to process sensitive data at inference time, such as healthcare records or financial documents assembled into a hidden \emph{context} before the system answers. Prior work has studied privacy risks primarily through \emph{jailbreaking} attacks that induce models to directly disclose sensitive content, but has largely overlooked the agentic setting where the context is assembled by the agent's own tool calls. We show that the agents we evaluate remain

Categories

Framework mappings

OWASP Top 10 for LLM Applications
  • LLM01Prompt Injection
  • LLM02Sensitive Information Disclosure
MITRE ATLAS
  • AML.T0024.000Infer Training Data Membership
  • AML.T0054LLM Jailbreak

Suggested from the entry's categories.

Cite

@misc{jha2026context,
  title = {{Context Inference Attacks Without Jailbreaks}},
  author = {Prince Jha and Samuele Poppi and Nils Lukas},
  year = {2026},
  month = aug,
  eprint = {2609.01663},
  archivePrefix = {arXiv},
  url = {https://arxiv.org/abs/2609.01663}
}