<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>adversarial data extraction from chatbots &#8211; Science</title>
	<atom:link href="https://scienmag.com/tag/adversarial-data-extraction-from-chatbots/feed/" rel="self" type="application/rss+xml" />
	<link>https://scienmag.com</link>
	<description></description>
	<lastBuildDate>Fri, 09 Oct 2026 01:52:13 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.1.3</generator>

<image>
	<url>https://scienmag.com/wp-content/uploads/2024/07/cropped-scienmag_ico-32x32.jpg</url>
	<title>adversarial data extraction from chatbots &#8211; Science</title>
	<link>https://scienmag.com</link>
	<width>32</width>
	<height>32</height>
</image> 
<site xmlns="com-wordpress:feed-additions:1">73899611</site>	<item>
		<title>Chatbots Never Forget: The Systemic Privacy Risks Hidden Inside Conversational AI</title>
		<link>https://scienmag.com/chatbots-never-forget-the-systemic-privacy-risks-hidden-inside-conversational-ai/</link>
		
		<dc:creator><![CDATA[Denise Maddox]]></dc:creator>
		<pubDate>Fri, 09 Oct 2026 01:52:13 +0000</pubDate>
				<category><![CDATA[Technology and Engineering]]></category>
		<category><![CDATA[adversarial data extraction from chatbots]]></category>
		<category><![CDATA[confidentiality risks of health and financial information in chatbots]]></category>
		<category><![CDATA[conversational AI]]></category>
		<category><![CDATA[conversational AI privacy risks]]></category>
		<category><![CDATA[data leakage]]></category>
		<category><![CDATA[data memorization in large language models]]></category>
		<category><![CDATA[Data Privacy]]></category>
		<category><![CDATA[differential privacy]]></category>
		<category><![CDATA[ethical considerations of privacy in conversational AI]]></category>
		<category><![CDATA[federated learning]]></category>
		<category><![CDATA[GDPR]]></category>
		<category><![CDATA[inference and re-identification threats in AI]]></category>
		<category><![CDATA[large language models]]></category>
		<category><![CDATA[machine unlearning]]></category>
		<category><![CDATA[memorization]]></category>
		<category><![CDATA[personal identifiable information leakage]]></category>
		<category><![CDATA[prompt injection]]></category>
		<category><![CDATA[re-identification]]></category>
		<category><![CDATA[regulatory challenges in AI privacy protection]]></category>
		<category><![CDATA[safeguarding user data in AI deployment]]></category>
		<category><![CDATA[surveillance]]></category>
		<category><![CDATA[surveillance and profiling through conversational AI]]></category>
		<category><![CDATA[systemic privacy vulnerabilities in chat-based systems]]></category>
		<category><![CDATA[training data vulnerabilities in large language models]]></category>
		<guid isPermaLink="false">https://scienmag.com/?p=251065</guid>

					<description><![CDATA[A comprehensive review warns that conversational AI agents pose systemic privacy risks, from memorized personal data and prompt injection attacks to the illusion that deleted information is truly gone.]]></description>
										<content:encoded><![CDATA[<p>Every day, billions of messages flow into conversational AI systems, and a startling proportion of them contain information most people would never dream of posting publicly. Health anxieties, financial troubles, relationship breakdowns, mental health struggles—all of it is typed casually into chat windows, often by users who have little idea where the data goes or how long it stays. A new review published in Discover Artificial Intelligence argues that this everyday habit of confiding in chatbots has created privacy risks that are not incidental bugs but systemic features of how large language models are built, trained, and deployed. The authors, led by Abdellah Ben yahia of Moulay Ismail University in Morocco, map five interconnected layers of danger: data memorization and leakage, adversarial extraction, inference and re-identification, surveillance and profiling, and the failure of regulatory frameworks to keep pace.</p>
<p>The technical heart of the problem is memorization. Large language models learn by absorbing vast quantities of text, and research has shown repeatedly that they can be coaxed into reproducing sequences from their training data verbatim—names, addresses, phone numbers, and other personally identifiable information. Studies cited in the review indicate that up to roughly three percent of the data in models comparable to GPT-4 and LLaMA can be attributed to training instances containing personal information. Crucially, the researchers distinguish between different forms of this vulnerability: verbatim memorization, where exact sequences resurface; semantic memorization, where content is reconstructed in altered wording and thus invisible to simple string-matching defenses; extractability, the probability of recovery under a given prompting budget; and exposure, the likelihood relative to an untrained baseline. Memorization tends to increase with model scale, and reinforcement learning from human feedback does not reliably suppress the disclosure of personal content.</p>
<p>Layered on top of memorization is a family of active attacks. Prompt injection allows adversaries to craft inputs that trick an agent into revealing private information from its training corpus or from other users&#8217; conversations. Jailbreaking and system prompt extraction techniques have been reported at success rates exceeding eighty percent in some studies, and the review describes so-called conditional poisoning attacks—dubbed SPECTRE and PARASITE by their developers—in which a malicious instruction lies dormant inside a system prompt until triggered, then exfiltrates conversation histories. These payloads can persist across sessions and evade detection. The threat surface widens further with agentic systems that browse the web and call external tools: indirect injection can hide in retrieved content the user never authored, compromised plugins can poison the toolchain, and manipulated parameters in the Model Context Protocol ecosystem have been shown to achieve exploitation success rates above eighty-five percent against mainstream coding agents, according to the OWASP Top 10 for Agentic Applications.</p>
<p>Even when nothing is copied out verbatim, conversational AI can betray its users through inference. Machine learning models can predict sensitive attributes—political affiliation, sexual orientation, health status, personality traits—from seemingly innocuous language, and the review notes that such inferences can reach very high accuracy. The classic finding that eighty-seven percent of the U.S. population can be uniquely identified from just ZIP code, gender, and date of birth takes on new force when an AI agent can link a probability-laden conversation history to public records, data broker databases, and social media profiles. The authors emphasize that no conversational benchmarks yet exist for re-identification with auxiliary linkage, and that quasi-identifier generalization techniques designed for structured databases simply do not transfer to unstructured dialogue.</p>
<p>Beyond individual harm, the review documents a quieter, collective danger: surveillance. AI agents embedded in workplaces monitor keystrokes, communication patterns, and even inferred emotional states to gauge productivity. Educational systems collect granular behavioral data on learners, including attention spans and affective states. Aggregated across millions of interactions, such data can support population-level profiling—predicting public opinion, health trends, or political dissent. The researchers point out that these capabilities are largely backed only by vendor documentation, with no independent, repeatable audits of commercial deployments, and that consent instruments are hollowed out by power asymmetries between employers, schools, and individuals.</p>
<p>Perhaps the most unsettling section of the review concerns what the authors call the illusion of deletion. When users press a delete button or edit a message, they typically believe the information is gone. In reality, consumer-facing controls usually reach only the application database—the first of seven storage layers that include vector indices, model parameters, retained training data, caches, logs, and backups. Personal information absorbed during fine-tuning becomes embedded in the model&#8217;s weights, and current machine unlearning techniques—exact removal, approximate unlearning, certified removal, and post-hoc fine-tuning—each fall short. Only the last two are even feasible for large transformer models, meaning certified parameter-level erasure is unavailable in any deployed agent. Worse, partial deletion can create an inference gap: by comparing model outputs before and after a deletion, adversaries can reconstruct what was removed. And the very presence of delete buttons can induce a deletion paradox, encouraging users to share more freely under a false sense of control.</p>
<p>The legal architecture fares little better. The GDPR and HIPAA were built for static, deterministic data processing, not for generative systems that infer, memorize, and operate across borders. Whether zeroing a parameter or its gradient constitutes erasure under GDPR Article 17 remains legally unsettled, and no jurisprudence yet addresses memorization or adversarial extraction. Many consumer chatbots fall outside the high-risk category of the EU AI Act, the United States lacks a comprehensive federal privacy law, and users in developing countries often enjoy even weaker protections while using the same platforms. Standards such as ISO/IEC 42001:2023, with its thirty-eight controls for AI management systems, offer a governance scaffold but do not resolve the fundamental conflict between machine memorization and data subject rights, nor do they define concrete privacy budgets or verification procedures for unlearning.</p>
<p>The review also weighs the psychological machinery driving over-disclosure. Anthropomorphic design—friendly names, empathetic language, conversational flow—consistently increases users&#8217; trust and emotional investment, producing what the authors term artificial intimacy. Even privacy-conscious individuals fall prey to the privacy paradox, sharing sensitive data with systems that simulate empathy. The evidence is genuinely contradictory: empathetic interfaces boost satisfaction and help-seeking, which is valuable in mental health support, while simultaneously elevating privacy risk. Notably, the authors flag the absence of randomized controlled trials comparing disclosure rates across anthropomorphic and neutral designs in high-stakes domains such as healthcare and financial advice—a gap they identify as critical for future research.</p>
<p>What can be done? The technical toolkit is real but conditional. Differential privacy injects calibrated noise under a mathematical guarantee, yet deployed systems cluster at privacy budgets of one to eight epsilon, where coherence degrades below roughly three and membership-inference protection fails at eight and above. Federated learning reduces storage risk but relocates the attack surface, since gradient leakage can reconstruct client inputs. On-device processing minimizes cloud exposure but remains computationally constrained. The authors&#8217; conclusion is that no single safeguard suffices; they propose a multi-layered framework combining classical privacy-preserving data publishing principles, technical defenses, and governance reform. Their bottom line is stark: the same properties that make conversational AI agents useful—memory, personalization, contextual understanding—are precisely what make them dangerous, and until deletion becomes technically real, regulation becomes enforceable, and users understand the bargain they are making, the convenience of chatting with a machine will keep coming at the price of personal data sovereignty.</p>
<p><strong>Subject of Research:</strong> Privacy risks of personal data exposure through conversational large language model agents</p>
<p><strong>Article Title:</strong> Systemic privacy risks of personal data exposure through conversational large language model agents</p>
<p><strong>Article References:</strong> Ben yahia, A., Kadir, I., El Harrak, E. F., Chisembe, S., Abdallaoui, A., El-Hmaidi, A., &amp; Dehbi, A. (2026). Systemic privacy risks of personal data exposure through conversational large language model agents. <em>Discover Artificial Intelligence, 6</em>(1), Article 1405. <a href="https://doi.org/10.1007/s44163-026-02431-5" rel="noopener noreferrer">https://doi.org/10.1007/s44163-026-02431-5</a></p>
<p><strong>Image Credits:</strong> AI Generated</p>
<p><strong>DOI:</strong> <a href="https://doi.org/10.1007/s44163-026-02431-5" rel="noopener noreferrer">10.1007/s44163-026-02431-5</a></p>
<p><strong>Keywords:</strong> large language models, conversational AI, data privacy, memorization, prompt injection, machine unlearning, re-identification, GDPR, surveillance, differential privacy, federated learning, data leakage</p>
]]></content:encoded>
					
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">251065</post-id>	</item>
	</channel>
</rss>
