Network-Level Prompt and Trait Leakage in Local Research Agents

Main:12 Pages
10 Figures
Bibliography:5 Pages
15 Tables
Appendix:3 Pages
Abstract
We show that Web and Research Agents (WRAs) -- language model-based systems that investigate complex topics on the Internet -- are vulnerable to inference attacks by passive network adversaries such as ISPs. These agents could be deployed \emph{locally} by organizations and individuals for privacy, legal, or financial purposes. Unlike sporadic web browsing by humans, WRAs visit domains with distinguishable timing correlations, enabling unique fingerprinting attacks.
View on arXivComments on this paper
