Privacy Risks and Leakage Pathways in Agentic and Multi-Agent AI Systems
Agentic and multi-agent AI systems are increasingly deployed as part of operational systems, introducing autonomous planning, delegation, persistent memory, tool use, and inter-agent coordination into data-driven decision making. These architectural properties challenge prevailing privacy assumptions because leakage may arise structurally from autonomy, coordination, persistence, and composition rather than only from isolated model outputs. This paper provides a structured synthesis of privacy risks and leakage pathways for agentic and multi-agent AI systems. We introduce a unifying abstraction that combines decentralized decision making with trace-based information-flow semantics, enabling reasoning about autonomy, coordination, persistent state, observability, and adversarial trace projections. Using this abstraction, we organize recurring privacy risks into five leakage pathways: autonomy-induced overexposure, coordination-driven information propagation, memory and persistent-state leakage, emergent and compositional inference, and observability and audit leakage. We further analyze why established privacy-enhancing technologies provide incomplete coverage in agentic settings, where static computation boundaries, single-agent assumptions, ephemeral state, and non-emergent behavior often fail. To ground the analysis, we implement a controlled multi-agent privacy sandbox with privacy-aware agents, tool-mediated workflows, adversarial trace projections, and LLM-backed validation. The results show that policy-checked privacy-aware execution reduces direct disclosure and adversarial inference advantage, while residual tool-mediated and semantic-hint leakage remains. The paper concludes by proposing new privacy requirements for agentic and multi-agent AI systems.
Authors
- Arash Mahboubi (ORCID: https://orcid.org/0000-0002-0487-0615)
- Hang Thanh Bui (ORCID: https://orcid.org/0000-0001-6851-7717)
- Keyvan Ansari (ORCID: https://orcid.org/0000-0002-9969-7682)
- Hamed Aboutorab (ORCID: https://orcid.org/0000-0002-9285-9917)
- Seyit Camtepe (ORCID: https://orcid.org/0000-0001-6353-8359)
Institutions
- Commonwealth Scientific and Industrial Research Organisation (AU)
- Murdoch University (AU)
- University of Canberra (AU)
- UNSW Sydney (AU)
- Health Sciences and Nutrition (AU)
Publication Details
- Journal
- ACM Transactions on Privacy and Security
- Published
- 2026-09-15
- DOI
- https://doi.org/10.1145/3848128
- Primary Topic
- Adversarial Robustness in Machine Learning
- Type
- article
- Field-Weighted Citation Impact
- 0.00