Abstract

Privacy leakage in LLM agents is commonly evaluated within individual components such as memory, retrieval, or tool-use pipelines, which makes it difficult to distinguish internal exposure from information that an external observer can actually recover. We present CIPL (Channel Inversion for Privacy Leakage), a channel-aware evaluation framework for black-box privacy leakage in LLM agents. CIPL represents a target through sensitive source, selection, assembly, execution, observation, and extraction stages and evaluates the transition from selected sensitive units to attacker-recoverable output under a shared protocol. Experiments across memory-based, retrieval-mediated, and tool-mediated targets, together with a BrowserUse live-agent case study, show that storage labels alone do not determine recoverability. Memory targets form a near-saturated reference case, retrieval-mediated leakage is frequently partial, and tool-mediated and live-agent leakage varies strongly with observation surface, prompt-to-channel alignment, retrieval depth, and provider behavior. A stratified semantic audit further identifies attacker-useful disclosures that canonical exact matching misses. CIPL therefore provides a common framework for comparing how internal sensitive dependence is realized as externally recoverable leakage across heterogeneous agent pipelines.

Keywords

Subject

Publication details

Journal
Not available
Open access
Green open access

Cite this article

APA 7

Huang, T., Wu, G., Zheng, G., Meng, J., Hou, C., Yang, X., Yang, X., & Xia, F. (2026). CIPL: A Channel-Aware Framework for Recoverable Privacy Leakage in LLM Agents. https://omanscience.com/en/articles/cipl-a-channel-aware-framework-for-recoverable-privacy-leakage-in-llm-agents

MLA 9

Huang, Tao, et al. "CIPL: A Channel-Aware Framework for Recoverable Privacy Leakage in LLM Agents." https://omanscience.com/en/articles/cipl-a-channel-aware-framework-for-recoverable-privacy-leakage-in-llm-agents.

Chicago (author–date)

Huang, Tao, Guosen Wu, Guolong Zheng, Jiayang Meng, Chen Hou, Xu Yang, Xuechao Yang, and Feng Xia. 2026. "CIPL: A Channel-Aware Framework for Recoverable Privacy Leakage in LLM Agents." https://omanscience.com/en/articles/cipl-a-channel-aware-framework-for-recoverable-privacy-leakage-in-llm-agents.

Harvard

Huang, T., Wu, G., Zheng, G., Meng, J., Hou, C., Yang, X., Yang, X. and Xia, F. (2026) 'CIPL: A Channel-Aware Framework for Recoverable Privacy Leakage in LLM Agents', Available at: https://omanscience.com/en/articles/cipl-a-channel-aware-framework-for-recoverable-privacy-leakage-in-llm-agents.

Vancouver

Huang T, Wu G, Zheng G, Meng J, Hou C, Yang X, et al. CIPL: A Channel-Aware Framework for Recoverable Privacy Leakage in LLM Agents. https://omanscience.com/en/articles/cipl-a-channel-aware-framework-for-recoverable-privacy-leakage-in-llm-agents

IEEE

T. Huang, G. Wu, G. Zheng, J. Meng, C. Hou, X. Yang, X. Yang, and F. Xia, "CIPL: A Channel-Aware Framework for Recoverable Privacy Leakage in LLM Agents," https://omanscience.com/en/articles/cipl-a-channel-aware-framework-for-recoverable-privacy-leakage-in-llm-agents.