← Latest papers
💬 NLP

Say Something Else: Rethinking Contextual Privacy as Information Sufficiency

This paper redefines contextual privacy for LLM agents as an Information Sufficiency task, introducing free-text pseudonymization as a superior strategy and a conversational evaluation protocol that reveals how single-message assessments underestimate privacy leakage compared to multi-turn interactions.

Original authors: Yunze Xiao, Wenkai Li, Xiaoyuan Wu, Ningshan Ma, Yueqi Song, Weihao Xuan

Published 2026-04-09
📖 5 min read🧠 Deep dive

Original authors: Yunze Xiao, Wenkai Li, Xiaoyuan Wu, Ningshan Ma, Yueqi Song, Weihao Xuan

Original paper licensed under CC BY 4.0 (http://creativecommons.org/licenses/by/4.0/). This is an AI-generated explanation of the paper below. It is not written or endorsed by the authors. For technical accuracy, refer to the original paper. Read full disclaimer

Imagine you have a very smart, helpful assistant (an AI) that writes messages for you. You tell it, "I need to ask my boss for time off," and you whisper the real reason: "I'm going to a therapy session."

The AI has to decide: How much of that secret should it tell your boss?

This paper is about finding the best way for the AI to protect your secrets without making you look suspicious or ruining the conversation. The researchers discovered that the way we usually test these AIs is flawed, and they found a new, better trick to keep your privacy safe.

Here is the breakdown in simple terms:

1. The Problem: The "Bad" Ways to Hide Secrets

Previously, AI systems had two main ways to handle your private info:

  • The "Silent Treatment" (Suppression): The AI just deletes the secret.
    • What happens: You say, "I need time off." The AI writes, "I need time off."
    • The flaw: Your boss reads it and thinks, "Wait, why? Is everything okay?" They ask again. Because the AI didn't give a reason, the boss gets suspicious and keeps asking. The silence actually invites more questions.
  • The "Vague Fog" (Generalization): The AI replaces the secret with a boring, broad category.
    • What happens: You say, "I'm going to therapy." The AI writes, "I have a private medical appointment."
    • The flaw: This sounds a bit shady. It's like wearing a trench coat and sunglasses in the middle of the day. It tells the boss, "I am hiding something!" The boss then thinks, "Okay, what kind of medical appointment?" and keeps digging.

The Big Mistake in Old Research:
Before this paper, scientists tested these methods by just looking at the first message. They thought, "Oh, the Vague Fog looks pretty good!" But they didn't test what happens when the boss asks, "So, what kind of appointment?" In the real world, people don't just read one message and stop; they chat back and forth. When you add those follow-up questions, the "Vague Fog" strategy collapses, and the secret leaks out.

2. The New Solution: The "Plausible Cover Story" (Pseudonymization)

The researchers introduced a third, smarter strategy called Pseudonymization.

Instead of deleting the info or being vague, the AI invents a specific, believable, but fake reason that fits the situation perfectly.

  • The Scenario: You need time off for therapy.
  • The AI's Reply: "I need time off to attend a professional training session."
  • Why it works:
    • It's specific: It answers the "Why?" immediately.
    • It's believable: It sounds normal and professional.
    • It's consistent: If the boss asks, "Oh, what are you learning?" the AI (and you) can say, "Oh, just some advanced project management skills," and the story holds up.

The Analogy:
Think of it like a spy movie.

  • Suppression is the spy saying nothing. The bad guy gets suspicious and starts searching the room.
  • Generalization is the spy saying, "I'm doing something important." The bad guy thinks, "What? Tell me!" and keeps pressing.
  • Pseudonymization is the spy saying, "I'm meeting a contact at the coffee shop." The bad guy thinks, "Oh, okay, that's normal," and leaves them alone. The spy didn't lie about where they are going (a coffee shop is a real place); they just lied about who they are meeting.

3. The Results: What the Study Found

The researchers tested this on 7 different super-smart AI models across 792 different scenarios (like talking to a boss, a friend, or a partner).

  • The "Cover Story" Wins: The "Pseudonymization" strategy was the clear winner. It kept secrets safe and kept the conversation flowing naturally.
  • The "Vague Fog" Fails: When the conversation went on for a few turns (like a real chat), the "Vague Fog" strategy failed miserably. The AI would get pressured and accidentally reveal the truth.
  • The "Silent Treatment" is Risky: Just saying nothing often made people ask more questions, which eventually led to the secret leaking anyway.

4. Why This Matters

This paper changes how we build AI assistants. It tells us that:

  1. Don't just test one message: You have to test how the AI handles a whole conversation, not just the first sentence.
  2. Don't just hide the truth: Sometimes, giving a plausible alternative is better than trying to hide the fact that you are hiding something.
  3. It's not lying, it's privacy: The authors argue that this isn't "deception." It's like telling your boss you have a "doctor's appointment" instead of "therapy." You are managing your privacy, not tricking them about how to do their job.

In a nutshell: If you want your AI to protect your secrets, don't tell it to be quiet or vague. Tell it to come up with a good, believable story that satisfies the other person's curiosity without revealing your actual secret. It's the art of the perfect "cover story."

Drowning in papers in your field?

Get daily digests of the most novel papers matching your research keywords — with technical summaries, in your language.

Try Digest →