PEPR 26 - Shadow Data in Tool Calls: The Privacy Leak Hiding in Plain Sight @UsenixOrg
PEPR 26 - Shadow Data in Tool Calls: The Privacy Leak Hiding in Plain Sight  @UsenixOrg
Uploaded June 2026 | Updated September 2026, 3 weeks ago
Shadow Data in Tool Calls: The Privacy Leak Hiding in Plain Sight

Shabista Shabista and Ravi Gupta, Independent; Mayank Kumar Raunak, Intel Corporation

"Run it locally and your data stays private." This assumption is dangerously wrong.
When an AI agent calls external tools—weather APIs, calendars, maps, search—the request itself leaks user data. A local agent asking "What's the weather at my doctor's office?" sends exact coordinates to a third party. The agent may be local, but your medical visit pattern isn't.
We are analyzing tool calls from a prototype smart home agent. Preliminary testing indicates that the majority leak personally identifiable or sensitive contextual information in the request parameters alone—before any response is processed. Location, health indicators, financial patterns, and relationship data routinely escape through tool call payloads.
This talk presents a working Tool Call Sanitizer deployed on Raspberry Pi that intercepts, analyzes, and generalizes outbound requests in real-time. We target significant reduction in data leakage with minimal degradation in task utility. Privacy engineering must extend beyond the agent to the entire tool ecosystem.

View the full PEPR '26 program at usenix.org/conference/pepr26/program
PEPR 26 - Shadow Data in Tool Calls: The Privacy Leak Hiding in Plain SightSREcon26 Americas - The Zero Trust Odyssey: Our Journey to Modernize Internal AccessNSDI 26 - Geminet: Learning the Duality-based Topology-Agnostic Update Operator for Lightweight...NSDI 26 - Observability Is Eating Your Cores: Fine-Grained Analysis of Microservice Metrics with...NSDI 26 - UNUM: A New Framework for Network ControlPEPR 26 - Private AI: Building Trust Through Verifiable ComputationSREcon26 Americas - Building SRE Culture (without SREs, Technically)NSDI 26 - Detecting and Diagnosing Errors in Serving Archived Web PagesNSDI 26 - SYMI: Efficient Mixture-of-Experts Training via Model and Optimizer State DecouplingPEPR 26 - Vision: Human-as-the-Unit Privacy Management with AI AgentsPEPR 26 - Surfacing Hidden Privacy Risks in Code: Lessons from LLM and Retrieval Assisted DetectionNSDI 26 - The GOODPUT System: A Machine Learning-Driven Optimization Framework for Dynamic...
USENIX |

PEPR '26 - Shadow Data in Tool Calls: The Privacy Leak Hiding in Plain Sight

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER