TAPER: Recoverable Observation Control for Privacy–Utility Balance in LLM Agents
Abstract
Tool-using LLM agents face an observation-level privacy–utility tradeoff: tool observations may contain task-critical evidence together with sensitive information unnecessary for the current task. Once exposed to the task agent, such information can affect later reasoning and actions, and downstream output checks cannot undo this exposure. Existing one-shot minimization may either retain sensitive content or remove required evidence; discarded evidence also cannot support later repair. We propose TAPER (Task-Aware Protected Evidence Routing), which derives a unified information boundary from the task, routes each observation into a task-agent-visible Public Task View and a default-hidden Protected State, and applies model-based privacy and task-sufficiency checks before exposure, repairing detected issues when necessary. When later operations require precise evidence, TAPER releases only the task-necessary protected content. Across 336 tasks from two agent privacy benchmarks, three task-agent backbones, and two evaluators, TAPER consistently combines strong task helpfulness with low final leakage and task-unnecessary visible exposure, achieving the strongest joint privacy–utility performance across all six model–evaluator settings.
est. 32% chance this paper gets accepted at ICLR 2027.
What do you think this paper will get?
All positions stay anonymous.