Leaky Thoughts: Large Reasoning Models Are Not Private Thinkers

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Green, Tommaso, Gubri, Martin, Puerto, Haritz, Yun, Sangdoo, Oh, Seong Joon
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866908570389315584
author Green, Tommaso
Gubri, Martin
Puerto, Haritz
Yun, Sangdoo
Oh, Seong Joon
author_facet Green, Tommaso
Gubri, Martin
Puerto, Haritz
Yun, Sangdoo
Oh, Seong Joon
contents We study privacy leakage in the reasoning traces of large reasoning models used as personal agents. Unlike final outputs, reasoning traces are often assumed to be internal and safe. We challenge this assumption by showing that reasoning traces frequently contain sensitive user data, which can be extracted via prompt injections or accidentally leak into outputs. Through probing and agentic evaluations, we demonstrate that test-time compute approaches, particularly increased reasoning steps, amplify such leakage. While increasing the budget of those test-time compute approaches makes models more cautious in their final answers, it also leads them to reason more verbosely and leak more in their own thinking. This reveals a core tension: reasoning improves utility but enlarges the privacy attack surface. We argue that safety efforts must extend to the model's internal thinking, not just its outputs.
format Preprint
id arxiv_https___arxiv_org_abs_2506_15674
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Leaky Thoughts: Large Reasoning Models Are Not Private Thinkers
Green, Tommaso
Gubri, Martin
Puerto, Haritz
Yun, Sangdoo
Oh, Seong Joon
Computation and Language
Artificial Intelligence
Cryptography and Security
We study privacy leakage in the reasoning traces of large reasoning models used as personal agents. Unlike final outputs, reasoning traces are often assumed to be internal and safe. We challenge this assumption by showing that reasoning traces frequently contain sensitive user data, which can be extracted via prompt injections or accidentally leak into outputs. Through probing and agentic evaluations, we demonstrate that test-time compute approaches, particularly increased reasoning steps, amplify such leakage. While increasing the budget of those test-time compute approaches makes models more cautious in their final answers, it also leads them to reason more verbosely and leak more in their own thinking. This reveals a core tension: reasoning improves utility but enlarges the privacy attack surface. We argue that safety efforts must extend to the model's internal thinking, not just its outputs.
title Leaky Thoughts: Large Reasoning Models Are Not Private Thinkers
topic Computation and Language
Artificial Intelligence
Cryptography and Security
url https://arxiv.org/abs/2506.15674