Ghost Tool Calls: Issue-Time Privacy for Speculative Agent Tools
Abstract
Tool-augmented agents are beginning to execute likely future tool calls speculatively to hide latency. When the agent abandons a speculated branch, those calls have already reached external services, carrying what the runtime guessed the user wanted. We call them ghost tool calls. Because no provider can be made to forget what it has logged, privacy must be decided when a speculative call goes out, not when its branch is dropped. We put the decision there: Speculative Tool Privacy Contracts label each proposed call and settle it before dispatch. What speculation gives away is both large and early. On a third-party agent benchmark, an observer who sees the agent's outgoing calls names what the user is deliberating about on 68% of tasks before the user confirms anything, against 21% from the calls the agent actually ends up making. Of the ghost calls that carry an intent at all, 31% name one the user never had. The leak recurs on two further domains and, independently, under a second speculator. The leak is separable from the speedup. Holding back only the sensitive speculative calls until the agent commits takes what an observer learns from the abandoned calls alone from 29.8% of tasks to 0.4%, while still allowing the agent to finish as many tasks and reuse every speculative call it would have. This costs latency: on live search, a median 6.8 points of the sequential baseline. The closest existing defense, restricting speculation to read-only calls, does not reach it: that helps only when the intent shows in which write the agent picks, and still leaks when the intent sits in what the agent reads.
est. 32% chance this paper gets accepted at ICLR 2027.
What do you think this paper will get?
All positions stay anonymous.