LATIDIA · Ciberseguridad
ASLEval: Medición del desplazamiento de la exposición a la privacidad en las sesiones de agentes de LLM
arXiv: 2609.18864v1Tipo de anuncio: nuevo Resumen: Las evaluaciones de privacidad de los agentes LLM que utilizan herramientas a menudo inspeccionan una acción designada, una respuesta final o un informe de atacante. Estos proxies locales pueden pasar por alto la exposición no autorizada si no
WhatsApp ↗Telegram ↗
La noticia
arXiv:2609.18864v1 Announce Type: new Abstract: Privacy evaluations of tool-using LLM agents often inspect a designated action, final response, or attacker report. These local proxies can miss unauthorized exposure elsewhere in a multi-step session and lack common ground truth across outlets, reports, and tool paths. We introduce privacy exposure displacement, the mismatch between a local evaluation proxy and target-grounded session exposure, and ASLEval, an authorization-aware framework that pre-registers a hidden target set, measures all declared visible exits, and reserves internal traces for diagnosis. Across multiple enterprise-style environments and independently implemented runtimes, we observe three recurring patterns. An expected-outlet-only view misses 46.9% of exposure recovered by the visible-exit union; attacker self-reports combine