August 2026Unreviewed
Context Inference Attacks Without Jailbreaks
Prince Jha, Samuele Poppi, Nils Lukas
Abstract
Agentic AI systems are increasingly deployed to process sensitive data at inference time, such as healthcare records or financial documents assembled into a hidden \emph{context} before the system answers. Prior work has studied privacy risks primarily through \emph{jailbreaking} attacks that induce models to directly disclose sensitive content, but has largely overlooked the agentic setting where the context is assembled by the agent's own tool calls. We show that the agents we evaluate remain
Categories
Framework mappings
OWASP Top 10 for LLM Applications
- LLM01Prompt Injection
- LLM02Sensitive Information Disclosure
MITRE ATLAS
- AML.T0024.000Infer Training Data Membership
- AML.T0054LLM Jailbreak
Suggested from the entry's categories.
Cite
@misc{jha2026context,
title = {{Context Inference Attacks Without Jailbreaks}},
author = {Prince Jha and Samuele Poppi and Nils Lukas},
year = {2026},
month = aug,
eprint = {2609.01663},
archivePrefix = {arXiv},
url = {https://arxiv.org/abs/2609.01663}
}