Abstract
Privacy leakage in LLM agents is commonly evaluated within individual components such as memory, retrieval, or tool-use pipelines, which makes it difficult to distinguish internal exposure from information that an external observer can actually recover. We present CIPL (Channel Inversion for Privacy Leakage), a channel-aware evaluation framework for black-box privacy leakage in LLM agents. CIPL represents a target through sensitive source, selection, assembly, execution, observation, and extraction stages and evaluates the transition from selected sensitive units to attacker-recoverable output under a shared protocol. Experiments across memory-based, retrieval-mediated, and tool-mediated targets, together with a BrowserUse live-agent case study, show that storage labels alone do not determine recoverability. Memory targets form a near-saturated reference case, retrieval-mediated leakage is frequently partial, and tool-mediated and live-agent leakage varies strongly with observation surface, prompt-to-channel alignment, retrieval depth, and provider behavior. A stratified semantic audit further identifies attacker-useful disclosures that canonical exact matching misses. CIPL therefore provides a common framework for comparing how internal sensitive dependence is realized as externally recoverable leakage across heterogeneous agent pipelines.
Keywords
Subject
Publication details
- Journal
- Not available
- Open access
- Green open access
Cite this article
APA 7
Huang, T., Wu, G., Zheng, G., Meng, J., Hou, C., Yang, X., Yang, X., & Xia, F. (2026). CIPL: A Channel-Aware Framework for Recoverable Privacy Leakage in LLM Agents. https://omanscience.com/en/articles/cipl-a-channel-aware-framework-for-recoverable-privacy-leakage-in-llm-agents
MLA 9
Huang, Tao, et al. "CIPL: A Channel-Aware Framework for Recoverable Privacy Leakage in LLM Agents." https://omanscience.com/en/articles/cipl-a-channel-aware-framework-for-recoverable-privacy-leakage-in-llm-agents.
Chicago (author–date)
Huang, Tao, Guosen Wu, Guolong Zheng, Jiayang Meng, Chen Hou, Xu Yang, Xuechao Yang, and Feng Xia. 2026. "CIPL: A Channel-Aware Framework for Recoverable Privacy Leakage in LLM Agents." https://omanscience.com/en/articles/cipl-a-channel-aware-framework-for-recoverable-privacy-leakage-in-llm-agents.
Harvard
Huang, T., Wu, G., Zheng, G., Meng, J., Hou, C., Yang, X., Yang, X. and Xia, F. (2026) 'CIPL: A Channel-Aware Framework for Recoverable Privacy Leakage in LLM Agents', Available at: https://omanscience.com/en/articles/cipl-a-channel-aware-framework-for-recoverable-privacy-leakage-in-llm-agents.
Vancouver
Huang T, Wu G, Zheng G, Meng J, Hou C, Yang X, et al. CIPL: A Channel-Aware Framework for Recoverable Privacy Leakage in LLM Agents. https://omanscience.com/en/articles/cipl-a-channel-aware-framework-for-recoverable-privacy-leakage-in-llm-agents
IEEE
T. Huang, G. Wu, G. Zheng, J. Meng, C. Hou, X. Yang, X. Yang, and F. Xia, "CIPL: A Channel-Aware Framework for Recoverable Privacy Leakage in LLM Agents," https://omanscience.com/en/articles/cipl-a-channel-aware-framework-for-recoverable-privacy-leakage-in-llm-agents.