Privacy Risks and Leakage Pathways in Agentic and Multi-Agent AI Systems

Agentic and multi-agent AI systems are increasingly deployed as part of operational systems, introducing autonomous planning, delegation, persistent memory, tool use, and inter-agent coordination into data-driven decision making. These architectural properties challenge prevailing privacy assumptions because leakage may arise structurally from autonomy, coordination, persistence, and composition rather than only from isolated model outputs. This paper provides a structured synthesis of privacy risks and leakage pathways for agentic and multi-agent AI systems. We introduce a unifying abstraction that combines decentralized decision making with trace-based information-flow semantics, enabling reasoning about autonomy, coordination, persistent state, observability, and adversarial trace projections. Using this abstraction, we organize recurring privacy risks into five leakage pathways: autonomy-induced overexposure, coordination-driven information propagation, memory and persistent-state leakage, emergent and compositional inference, and observability and audit leakage. We further analyze why established privacy-enhancing technologies provide incomplete coverage in agentic settings, where static computation boundaries, single-agent assumptions, ephemeral state, and non-emergent behavior often fail. To ground the analysis, we implement a controlled multi-agent privacy sandbox with privacy-aware agents, tool-mediated workflows, adversarial trace projections, and LLM-backed validation. The results show that policy-checked privacy-aware execution reduces direct disclosure and adversarial inference advantage, while residual tool-mediated and semantic-hint leakage remains. The paper concludes by proposing new privacy requirements for agentic and multi-agent AI systems.

Authors

Institutions

Publication Details

Journal
ACM Transactions on Privacy and Security
Published
2026-09-15
DOI
https://doi.org/10.1145/3848128
Primary Topic
Adversarial Robustness in Machine Learning
Type
article
Field-Weighted Citation Impact
0.00
Controls
|||
ALL TIME
JAN
FEB
MAR
APR
MAY
JUN
JUL
AUG
SEP
article

Privacy Risks and Leakage Pathways in Agentic and Multi-Agent AI Systems

Arash Mahboubi, Hang Thanh Bui, Keyvan Ansari, Hamed Aboutorab et al.
ACM Transactions on Privacy and Security
Adversarial Robustness in Machine Learning
article

Privacy Risks and Leakage Pathways in Agentic and Multi-Agent AI Systems

Arash Mahboubi, Hang Thanh Bui, Keyvan Ansari, Hamed Aboutorab, Seyit Camtepe
article en

Abstract

Agentic and multi-agent AI systems are increasingly deployed as part of operational systems, introducing autonomous planning, delegation, persistent memory, tool use, and inter-agent coordination into data-driven decision making. These architectural properties challenge prevailing privacy assumptions because leakage may arise structurally from autonomy, coordination, persistence, and composition rather than only from isolated model outputs. This paper provides a structured synthesis of privacy risks and leakage pathways for agentic and multi-agent AI systems. We introduce a unifying abstraction that combines decentralized decision making with trace-based information-flow semantics, enabling reasoning about autonomy, coordination, persistent state, observability, and adversarial trace projections. Using this abstraction, we organize recurring privacy risks into five leakage pathways: autonomy-induced overexposure, coordination-driven information propagation, memory and persistent-state leakage, emergent and compositional inference, and observability and audit leakage. We further analyze why established privacy-enhancing technologies provide incomplete coverage in agentic settings, where static computation boundaries, single-agent assumptions, ephemeral state, and non-emergent behavior often fail. To ground the analysis, we implement a controlled multi-agent privacy sandbox with privacy-aware agents, tool-mediated workflows, adversarial trace projections, and LLM-backed validation. The results show that policy-checked privacy-aware execution reduces direct disclosure and adversarial inference advantage, while residual tool-mediated and semantic-hint leakage remains. The paper concludes by proposing new privacy requirements for agentic and multi-agent AI systems.

ACM Transactions on Privacy and Security
Commonwealth Scientific and Industrial Research Organisation (AU), Murdoch University (AU), University of Canberra (AU), UNSW Sydney (AU), Health Sciences and Nutrition (AU)
Peace, Justice and strong institutions
Openalex Percentile: Top 8%
Adversarial Robustness in Machine Learning
AI Navigator

Ask Laika to Summarize, Analyze, and Connect papers live on the map.

Summarize Papers & Methodologies

Extract key findings, datasets, and comparative methods across publications.

Benchmark Rankings & Visual Analytics

Rank top research institutions, authors, funders, topics, and journals by Field-Weighted Citation Impact (FWCI) and paper volume with instant charts.

Connect Distant Disciplines

Bridge topological clusters on the map to find hidden collaborative intersections.