acceptodds
Under review as a conference paper at ICLR 2027

MAPLEBench: A Benchmark for Multi-Agent Privacy in Long-horizon Executions

Abstract

With AI agents being increasingly entrusted with long-horizon tasks, they are often expected to access and process sensitive information while interacting with potentially untrusted tools and external agents. Existing privacy benchmarks, however, commonly rely on short interactions, restricted tool interfaces, or simulated environments, leaving leakage risks specific to long-horizon trajectories underexplored. We introduce MAPLEBench, a benchmark for evaluating privacy leakage in realistic long-horizon multi-agent workflows where leakage may emerge, propagate, or resurface across extended agent interactions. MAPLEBench comprises 51 tasks with scenarios that require contextually appropriate handling of sensitive information. Agents operate in sandboxed environments with real tool access, while multi-agent settings expose them to adversarial third-party agent interactions. Our evaluation framework combines a Disclosure Detector for identifying sensitive-information exposure with an information-theoretic Leakage Estimator for quantifying leakage severity over complete trajectories. These detectors overcome multiple challenges in extending existing detection mechanisms into long-horizon trajectories. Evaluations of five LLMs as agent backbones across single- and multi-agent settings reveal that sensitive information often resurfaces after prolonged dormancy. Surprisingly, we find that privacy-enhancing instructions do not consistently reduce leakage and can sometimes exacerbate it, highlighting the limitations of prompt-based privacy safeguards.

Then back it, or bet against it.

Related papers

Open the market on this paper to see 7 more related papers.