Beyond PII: How Users Attempt to Estimate and Mitigate Implicit LLM Inference

Fuente: arXiv
Guardado en:
Detalles Bibliográficos
Autores principales: Wang, Synthia, Peddinti, Sai Teja, Taft, Nina, Feamster, Nick
Formato: Preprint
Publicado: 2025
Materias:
Acceso en línea:
Etiquetas: Agregar Etiqueta
Sin Etiquetas, Sea el primero en etiquetar este registro!
_version_ 1866916950180888576
author Wang, Synthia
Peddinti, Sai Teja
Taft, Nina
Feamster, Nick
author_facet Wang, Synthia
Peddinti, Sai Teja
Taft, Nina
Feamster, Nick
contents Large Language Models (LLMs) such as ChatGPT can infer personal attributes from seemingly innocuous text, raising privacy risks beyond memorized data leakage. While prior work has demonstrated these risks, little is known about how users estimate and respond. We conducted a survey with 240 U.S. participants who judged text snippets for inference risks, reported concern levels, and attempted rewrites to block inference. We compared their rewrites with those generated by ChatGPT and Rescriber, a state-of-the-art sanitization tool. Results show that participants struggled to anticipate inference, performing a little better than chance. User rewrites were effective in just 28\% of cases - better than Rescriber but worse than ChatGPT. We examined our participants' rewriting strategies, and observed that while paraphrasing was the most common strategy it is also the least effective; instead abstraction and adding ambiguity were more successful. Our work highlights the importance of inference-aware design in LLM interactions.
format Preprint
id arxiv_https___arxiv_org_abs_2509_12152
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Beyond PII: How Users Attempt to Estimate and Mitigate Implicit LLM Inference
Wang, Synthia
Peddinti, Sai Teja
Taft, Nina
Feamster, Nick
Human-Computer Interaction
Artificial Intelligence
Large Language Models (LLMs) such as ChatGPT can infer personal attributes from seemingly innocuous text, raising privacy risks beyond memorized data leakage. While prior work has demonstrated these risks, little is known about how users estimate and respond. We conducted a survey with 240 U.S. participants who judged text snippets for inference risks, reported concern levels, and attempted rewrites to block inference. We compared their rewrites with those generated by ChatGPT and Rescriber, a state-of-the-art sanitization tool. Results show that participants struggled to anticipate inference, performing a little better than chance. User rewrites were effective in just 28\% of cases - better than Rescriber but worse than ChatGPT. We examined our participants' rewriting strategies, and observed that while paraphrasing was the most common strategy it is also the least effective; instead abstraction and adding ambiguity were more successful. Our work highlights the importance of inference-aware design in LLM interactions.
title Beyond PII: How Users Attempt to Estimate and Mitigate Implicit LLM Inference
topic Human-Computer Interaction
Artificial Intelligence
url https://arxiv.org/abs/2509.12152