Contextual Privacy in Agentic Workflows is a Systems Problem: A Benchmark, Auditor & Guard
Abstract
Agentic systems handle sensitive personal data on users’ behalf, often across multiple tools and stages. Privacy work has focused on what the user shares and what the agent finally outputs. The trajectory between the user’s input and the agent’s final output remains largely unmeasured, even though it is where much of the exposure occurs: agents request more data than the task requires, tools return it indiscriminately, and private information reaches parties and stages where it does not belong. We introduce Σ-Bench, a benchmark of 677 privacy-sensitive scenarios grounded in everyday personal life, paired with PrivacyTrace, a typed-flow graph that records every data flow violation across four execution stages. Across 16 frontier agent models on a stratified 85-scenario subset, we find pipeline viola- tions in 83–99% of executions, compared with output leakage of 33–55%. Thus, output-only evaluation undercounts exposure by at least 1.5×, over 2× for most models. While privacy-aware prompting does not reliably reduce privacy violation, higher task success is also associated with greater leakage. We further introduce PrivacyTraceGuard, our runtime guard, that allows, filters, or blocks each flow at its boundary. It intervenes at every pipeline stage and reduces both pipeline and output violations. Filtering reduces pooled output leakage from 43.8% to 17.1%, and blocking to 6.7%, while pipeline violations remain 80.1% and 77.5%, respectively. These results show that privacy is a property of the full execution and requires boundary-level auditing and intervention. Code, data, and trace artifacts will be released.
Then back it, or bet against it.
Related papers
Open the market on this paper to see 7 more related papers.