Fuzzing Inference-Time Privacy Risks in Deployed Large Language Models
Authors/Creators
Description
Large Language Models (LLMs) are increasingly deployed in applications that process sensitive information, raising concerns about privacy violations during inference. While existing approaches primarily focus on training-time guarantees and static defenses, they provide limited insight into whether deployed models exhibit privacy-violating behavior at runtime. In this paper, we propose a fuzzing-based testing framework for evaluating inference-time privacy risks in LLMs under black-box conditions. The framework operationalizes privacy risks as executable artifacts composed of structured test seeds, risk-specific prompt transformations, and explicit test oracles. We instantiate the framework for the misuse and malicious use of personal data risk using canary injection and multi-message conversational trajectories. An empirical evaluation across three commercial LLMs demonstrates that privacy failures can be systematically elicited, are highly dependent on conversational structure and identifier representation, and vary substantially across models. The results indicate that privacy can be treated as a testable behavioral property at inference time, enabling comparative and risk-driven evaluation of deployed LLMs.
Files
0_Summary-1.pdf
Files
(1.2 MB)
| Name | Size | Download all |
|---|---|---|
|
md5:bcf907fd812d04c988425a722cd3b362
|
43.0 kB | Preview Download |
|
md5:67693f2b0792d15befdabbb0a1b1b4e2
|
69.7 kB | Preview Download |
|
md5:a1c097e5b5be96bf28cebc21828e23ff
|
664 Bytes | Download |
|
md5:61c637637503944bed68264940d6556a
|
815 Bytes | Download |
|
md5:a868af907ee1bac397bf39e6d02d56db
|
908 Bytes | Download |
|
md5:a38cd41366b0fbad80adbc82949a3c99
|
1.3 kB | Download |
|
md5:e83d2034be3d339ff1b1397068ef8183
|
327.4 kB | Preview Download |
|
md5:788c6dd6b1d75c85d09b5fb6892fc9a1
|
437 Bytes | Download |
|
md5:a10eff5e3035cc4c52d0796a607b55ce
|
918 Bytes | Download |
|
md5:aa5053484e537cb49e1d56bbc0850fc8
|
403.7 kB | Preview Download |
|
md5:a61e4f26db08ce88bb7e433229bc815c
|
369.1 kB | Preview Download |
|
md5:7580dc07580e3c05b95eb8decd1a8d48
|
928 Bytes | Preview Download |
|
md5:0dbb5652f6eb44cffd79f031f2fdf950
|
597 Bytes | Download |
|
md5:7e7c862e13af1b9470f93ac5e5fa8cc6
|
629 Bytes | Download |