arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2608.24957cs.CRcs.SE

ToolMinimize:审计与重写大语言模型智能体的工具调用以最小化隐私暴露

ToolMinimize: Auditing and Rewriting LLM Agent Tool Calls to Minimize Privacy Exposure

Wenbiao Li, Yuqiao Xu

AI总结:

ToolMinimize是一款中间件,通过拦截并重写LLM智能体的工具调用参数,结合schema感知分析与四种操作,在保证100%任务有效性的同时大幅降低隐私暴露,可选层可进一步提升效果,延迟极低。

AI中文摘要:

大语言模型(LLM)智能体在工具调用参数中通常会包含超出被调用工具所需的隐私敏感数据(PSD),每次调用都会跨越与第三方服务的信任边界。对三个生产级大语言模型(GPT-4o、Claude 3.5 Sonnet、Llama-3.3-70B)的受控测量显示,在默认提示下,81%至88%的工具调用包含不必要的隐私敏感数据;明确的隐私指令仍会导致36%至76%的过度分享。现有防御措施通过允许/阻止调用或标记数据流(信息流控制)来管控,但无法重写参数值,且个人身份信息(PII)检测工具会遗漏“纪念斯隆凯特琳癌症中心”这类隐含诊断的隐私敏感数据。我们提出ToolMinimize,这是一种中间件,可拦截工具调用并重写其参数为工具功能所需的最小数据,结合模式感知的必要性分析与移除、泛化、替换、截断四种操作。对上述三个大语言模型的307次工具调用进行的实时验证显示,隐私成本降低了81.2%至92.0%,且达到100%的参数级任务有效性(双单侧t检验(TOST)等效性p<0.001,Δ=1.0);对25个未标注的模型上下文协议(MCP)模式,在无“最小必要”元数据的情况下,隐私成本降低了79.0%。可选的LLM内容必要性层会从原本必要的自由文本字段中剥离与任务无关的隐私敏感数据,使实时大语言模型的降低幅度提升至85.1%至95.6%,作者定义模式的降低幅度从71.1%提升至90.9%,平均延迟为1.77毫秒。

英文摘要:

LLM agents routinely include privacy-sensitive data (PSD) in tool call arguments beyond what the invoked tools require, crossing trust boundaries to third-party services on every invocation. A controlled measurement on three production LLMs (GPT-4o, Claude 3.5 Sonnet, Llama-3.3-70B) shows that 81--88\% of tool calls include unnecessary PSD under default prompts; explicit privacy instructions still leave 36--76\% over-sharing. Existing defenses gate calls (allow/block) or label flows (information-flow control) but cannot \emph{rewrite} argument values, and PII detection tools miss implicit PSD like ``Memorial Sloan Kettering'' (a hospital name that implies a diagnosis). We present \system{}, a middleware that intercepts tool calls and rewrites their arguments to the minimum data necessary for tool functionality, combining schema-aware necessity analysis with four operations: removal, generalization, substitution, and truncation. Live validation on 307 tool calls across the three LLMs above reduces privacy cost by 81.2--92.0\% at 100\% argument-level task validity (TOST equivalence $p{<}0.001$ at $Δ{=}1.0$); on 25 unannotated Model Context Protocol (MCP) schemas, by 79.0\% with no \texttt{minimum\_necessary} metadata. An optional LLM content-necessity layer strips task-irrelevant PSD from otherwise-necessary free-text fields, raising live-LLM reduction to 85.1--95.6\% and author-schema reduction from 71.1\% to 90.9\%. Median latency is 1.77\,ms.

↑