REVIEW 3 major objections 5 minor 56 references
Understanding Users' Privacy Perceptions Towards LLM's RAG-based Memory
T0 review · 3 major / 5 minor · reviewed 2026-08-05 · deepseek-v4-flash
Pith's one-line read Users of RAG-based LLM memory rely on four mental models—most of them inaccurate—and those models directly drive their privacy choices, from oversharing to refusing the feature.
desk verdict Careful interview study of LLM memory perceptions, but the RQ1 taxonomy likely conflates RAG with contextual memory; still worth refereeing. read the letter →
The pith
A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.
The reading
What carries the argument
The key machinery is the four-model mental-model taxonomy (transient buffer, training-data extension, active information processor, acknowledged non-understanding), elicited through semi-structured interviews centered on ChatGPT's RAG memory. The taxonomy does the argumentative work: each model is paired with a distinct privacy-behavior consequence and a distinct design need. A second piece of machinery is the memory-lifecycle grid—generation, management, usage, updating—which organises both the challenges users report and the granular controls they demand. The analysis uses thematic coding with independent double-coding and an inter-rater reliability of 0.90.
What would settle it
Run the same interview without the RAG primer; if the four mental models do not appear spontaneously, the taxonomy is partly built by the study's own explanation. Alternatively, in a deployed memory system, compare disclosure rates of users who believe memory is transient against logged persistence; if they do not disclose more sensitive information, the 'inaccurate mental models exacerbate privacy risk' link fails.
Extended reading notes
Core claim
The paper's central discovery is a taxonomy of four mental models that users hold about RAG-based LLM memory. In the first, memory is a transient, dialogue-specific buffer that resets when the chat window closes; in the second, memory is an extension of the core training data, so personal conversations are absorbed into the model's public knowledge; in the third, memory is an active information-processing mechanism that summarises, selects, and infers; and the fourth is an openly acknowledged absence of any working model. The paper argues that these models shape privacy behavior in opposing directions: the transient-buffer model creates a false sense of security and encourages oversharing, w
Load-bearing premise
The taxonomy rests on two assumptions: that the short RAG description given to participants before the interview did not steer the mental models they reported, so the four models reflect pre-existing user conceptions rather than ones induced by the study; and that 18 Chinese students' self-reports stand in for user perceptions generally—the second is acknowledged in the paper, the first is not.
Editorial extensions
If this is right
- Users who see memory as a transient dialogue buffer will disclose more sensitive information than users who see it as a training-data extension, because the former believe the data disappears when the chat ends.
- Users who see memory as training-data absorption will withhold information even when the system stores it in a separate user-specific memory layer, so transparency about architecture changes disclosure behavior.
- There is a consensus demand for granular lifecycle control: decide what is committed to memory, edit or delete individual memories, control which memories are active for a task, and be told when the system infers something.
- Design implications follow directly: modular memory 'workspaces' or personas, provenance labels on each memory entry, and a 'review and commit' step before a system-generated memory is stored.
- Because inaccurate mental models directly exacerbate privacy risk, user education and transparent interfaces should be treated as privacy safeguards rather than optional usability polish.
Reading between the lines
- The paper's logic implies that mental-model accuracy is a measurable risk factor; a survey instrument that classifies users into the four models could predict who is most likely to overshare or under-share.
- The uniform demand for granular control may collide with the cognitive-load and privacy-fatigue effects the paper itself cites; a testable extension is whether 'review and commit' prompts stay effective after repeated use or become rubber-stamped.
- Because all participants were young, educated, Chinese, and interviewed about ChatGPT, the taxonomy is a hypothesis for other user populations; replicating with non-student, non-Chinese, and non-ChatGPT users would reveal which models are product-specific and which are general.
- The paper's framing suggests a direct A/B test: surfacing exactly which memory was retrieved and why (via footnotes or tooltips) should measurably shift users' disclosure and deletion behavior if the mental-model story is correct.
Editorial analysis
A structured set of objections, weighed in public.
Referee Report
Summary. This paper reports a qualitative interview study with 18 Chinese users of LLM-based conversational agents, focused on their mental models of RAG-based memory, their privacy calculus and protective strategies, and their challenges and expectations for memory system design. The authors identify four mental models (memory as a transient dialogue-specific buffer, as an extension of core training data, as an active information-processing mechanism, and acknowledged lack of understanding), describe a range of perceived benefits/risks and user-devised protections, and distill design implications for transparency and granular user control. The central claim is that users' often inaccurate conceptualizations of how memory works directly exacerbate privacy risks.
Significance. If the results stand, the paper contributes a useful taxonomy of user mental models of LLM memory, an area that is timely given the rapid deployment of persistent memory features in commercial assistants. The study is carefully executed at the level of qualitative method: two coders, Cohen's Kappa 0.90 on 20% of the data, and extensive verbatim quotes support the reported themes. The articulation of design implications across architecture, interface, and interaction layers is a strength and should be of interest to CHI and privacy communities. However, the central contribution--the RQ1 taxonomy as a taxonomy of mental models of RAG-based memory--carries a construct-validity risk that the paper itself partially acknowledges but does not bound.
major comments (3)
- [§4.1 and §5.1; Appendix B.1] The RQ1 taxonomy is the paper's first contribution, but the evidence does not establish that these are mental models of RAG-based memory specifically. Section 5.1 concedes that 'some memories participants mentioned are not RAG-based memories' and that participants confused different memory types. The quotes supporting Mental Model 1 (P1: 'memory can only be maintained in the same dialogue window'; P5: 'exists in the same dialogue, but not across dialogues') describe session-limited contextual memory, not the persistent, cross-session RAG memory that is the paper's target. Treating these as misconceptions about RAG misattributes a correct model of a different subsystem to the target construct. Moreover, Appendix B.1 states that participants were given a technical description of RAG before the elicitation questions, creating a priming risk that the paper never discusses. The design implica
- [Abstract and §5.1, second paragraph] The causal formulation 'users' varying and often inaccurate conceptualization of how memory functions can directly exacerbate these risks' goes beyond what the interview data can support. The study is cross-sectional and self-report based; it can show an association between a stated mental model and reported disclosure behavior (e.g., Mental Model 1 leading to a 'false sense of security'), but it does not measure actual risk exposure or demonstrate a causal pathway. The paper itself provides no quantitative or longitudinal evidence that an inaccurate mental model 'directly' increases privacy harm. This overstatement appears in the abstract and is load-bearing for the paper's motivation. The authors should soften the claim to reflect that the data show an association or plausible mechanism, or add a direct measurement of the proposed link (e.g., a scenario-based experiment).
- [§5.4 and abstract] The paper's generalizability claim is broader than the sample supports. Section 5.4 acknowledges the participants are 'Chinese users under Chinese regulations' and 'biased towards young students.' The abstract and introduction nevertheless present findings as about 'users' without scope qualifications. This is acknowledged in the limitations, so it is not a hidden flaw, but it is load-bearing for the strength of the overall contribution. I recommend adding explicit scope qualifiers in the abstract (e.g., 'among 18 young Chinese users') and in the contribution statements, or providing a reasoned argument for why the patterns are likely to generalize to other populations. Without this, the title 'Understanding Users' Privacy Perceptions...' overstates the empirical base.
minor comments (5)
- [Throughout] Typographical errors: 'mentral' (RQ1), 'improvec' (§4.2.1), 'limitaitons' and 'certered' (§5.4), 'coarsed' (§5.2). A copyediting pass is needed.
- [Table 1] The 'Occupation /' column header is incomplete and several rows are malformed, making the demographics table hard to read. The 'Usage experience' column lists many tools but the format is inconsistent.
- [Reference list] The paper self-cites [43]-[45] in the related work and discussion. This is acceptable, but the reader should verify that these citations are necessary and not excessive; the overlap with [44] ('Ghost of the past') in particular appears substantial, and the added value over that prior work should be clarified in the introduction.
- [Appendix B.1] The interview script asks 'In your view, how does the memory mechanisms of the a Large Language Model' operate?' This is grammatically awkward. More substantively, the script immediately follows the technical primer with an open question about 'memory mechanisms,' which may have primed participants to describe the primer's content. Consider reporting the exact wording of the primer in Chinese and English for transparency.
- [§4.3.2, 'Regarding usage'] The quote from P10 'will only tell you what the updated memory is, won't tell you which memory was used' appears without a clear source attribution (the participant ID is in the preceding sentence, but the quote itself is not marked as a quote in the text). Check punctuation consistency.
Circularity Check
No significant circularity; the mental-model taxonomy is inductively derived from interview data and does not reduce to its inputs.
full rationale
This paper is a qualitative thematic analysis, not a derivation. The central claims—four mental models of LLM memory (Section 4.1), privacy calculus and protective strategies (Section 4.2), and lifecycle-control expectations (Section 4.3)—are generated inductively from 18 semi-structured interviews via iterative coding with inter-rater reliability (Section 3.3, Cohen's Kappa 0.90). There is no fitted parameter, no equation, and no uniqueness theorem invoked; the findings are not equivalent by construction to the interview script or the RAG primer. The self-citations ([43], [44], [45]) appear only as related work or as supporting references for general points about agency and anonymization (Sections 2.3 and 5.2); none is load-bearing for the empirical claims, so they do not constitute circularity under the stated rules. The paper itself flags two limitations that are relevant but not circular: Section 5.4 notes the sample is Chinese students and therefore not generalizable, and Section 5.1 admits that 'some memories participants mentioned are not RAG-based memories' and that participants confused memory types. This is a construct-validity concern about whether RQ1 measures mental models of RAG memory specifically, but it is an acknowledged empirical limitation, not a reduction of the result to its inputs. The psychological priming risk of Appendix B.1 is likewise a methodological concern, not circularity: the taxonomy could have been shaped by the primer, but the paper does not define the outcome in terms of the primer or fit the taxonomy to it. Therefore the paper's central contribution has independent empirical content and receives a circularity score of 0.
Assumptions & free parameters
assumptions (4)
- domain assumption Self-reports from 18 self-selected Chinese users, mostly students aged 19-27, are sufficient to characterize user mental models and privacy perceptions of LLM memory.
- domain assumption Providing participants with a technical description of RAG before eliciting their mental models does not unduly anchor their responses.
- domain assumption Thematic analysis with two independent coders (Cohen's Kappa 0.90 on 20% of data) yields themes that reflect participants' actual perceptions.
- domain assumption Participants' self-reported practices and concerns, without behavioral or system-log triangulation, are treated as accurate evidence of their actual privacy behavior.
Cite this review
Pith. "Pith review of Understanding Users' Privacy Perceptions Towards LLM's RAG-based Memory." pith.science (2026). https://pith.science/paper/URVAW7WP
@misc{pith2026250807664,
author = {Pith},
title = {Pith review of: Understanding Users' Privacy Perceptions Towards LLM's RAG-based Memory},
year = {2026},
howpublished = {\url{https://pith.science/paper/URVAW7WP}},
note = {Machine review of arXiv:2508.07664}
}
read the original abstract
Large Language Models (LLMs) are increasingly integrating memory functionalities to provide personalized and context-aware interactions. However, user understanding, practices and expectations regarding these memory systems are not yet well understood. This paper presents a thematic analysis of semi-structured interviews with 18 users to explore their mental models of LLM's Retrieval Augmented Generation (RAG)-based memory, current usage practices, perceived benefits and drawbacks, privacy concerns and expectations for future memory systems. Our findings reveal diverse and often incomplete mental models of how memory operates. While users appreciate the potential for enhanced personalization and efficiency, significant concerns exist regarding privacy, control and the accuracy of remembered information. Users express a desire for granular control over memory generation, management, usage and updating, including clear mechanisms for reviewing, editing, deleting and categorizing memories, as well as transparent insight into how memories and inferred information are used. We discuss design implications for creating more user-centric, transparent, and trustworthy LLM memory systems.
Reference graph
Works this paper leans on
-
[1]
I know even if you don’t tell me
Sumit Asthana, Jane Im, Zhe Chen, and Nikola Banovic. 2024. " I know even if you don’t tell me": Understanding Users’ Privacy Preferences Regarding AI-based Inferences of Sensitive Information for Personalization. In Proceedings of the 2024 CHI Conference on Human Factors in Computing Systems . 1–21
2024
-
[2]
Shubhi Asthana, Bing Zhang, Ruchi Mahindru, Chad DeLuca, Anna Lisa Gentile, and Sandeep Gopisetty. 2025. Deploying Privacy Guardrails for LLMs: A Com- parative Analysis of Real-World Applications. arXiv preprint arXiv:2501.12456 (2025)
work page Pith review arXiv 2025
-
[3]
Sanghwan Bae, Donghyun Kwak, Soyoung Kang, Min Young Lee, Sungdong Kim, Yuin Jeong, Hyeri Kim, Sang-Woo Lee, Woomyoung Park, and Nako Sung
-
[4]
Michael Bailey, David Dittrich, Erin Kenneally, and Doug Maughan. 2012. The menlo report. IEEE Security & Privacy 10, 2 (2012), 71–75
2012
-
[5]
Natã M Barbosa, Zhuohao Zhang, and Yang Wang. 2020. Do Privacy and Security Matter to Everyone? Quantifying and Clustering{User-Centric} Considerations About Smart Home Device Adoption. In Sixteenth Symposium on Usable Privacy and Security (SOUPS 2020) . 417–435
work page 2020
-
[6]
Tom L Beauchamp et al. 2008. The belmont report. The Oxford textbook of clinical research ethics (2008), 149–155
work page 2008
-
[7]
Ann Cavoukian et al. 2009. Privacy by design: The 7 foundational principles. Information and privacy commissioner of Ontario, Canada 5, 2009 (2009), 12
work page 2009
-
[8]
Hanbyul Choi, Jonghwa Park, and Yoonhyuk Jung. 2018. The role of privacy fatigue in online privacy behavior. Computers in Human Behavior 81 (2018), 42–51
2018
Show all 56 references
-
[9]
Giana Eckhardt. 2002. Culture’s consequences: Comparing values, behaviors, institutions and organisations across nations. Australian journal of management 27, 1 (2002), 89–94
2002
-
[10]
Wenqi Fan, Yujuan Ding, Liangbo Ning, Shijie Wang, Hengyun Li, Dawei Yin, Tat-Seng Chua, and Qing Li. 2024. A survey on rag meeting llms: Towards retrieval-augmented large language models. In Proceedings of the 30th ACM SIGKDD Conference on Knowledge Discovery and Data Mining ...
2024
-
[11]
Google PAIR. 2019. People + AI Guidebook . Technical Report. Google Research. https://design.google/aiguidebook/
2019
-
[12]
Ziheng Huang, Sebastian Gutierrez, Hemanth Kamana, and Stephen Macneil
-
[13]
Carolin Ischen, Theo Araujo, Hilde Voorveld, Guda van Noort, and Edith Smit
-
[14]
Siwon Kim, Sangdoo Yun, Hwaran Lee, Martin Gubri, Sungroh Yoon, and Seong Joon Oh. 2023. Propile: Probing privacy leakage in large language models. Understanding Users’ Privacy Perceptions Towards LLM’s RAG-based Memory Conference acronym ’XX, June 03–05, 2018, Woodstock, NY A...
2023
-
[15]
Robert S Laufer and Maxine Wolfe. 1977. Privacy as a concept and a social issue: A multidimensional developmental theory. Journal of social Issues 33, 3 (1977), 22–42
1977
-
[16]
Haoran Li, Dadi Guo, Donghao Li, Wei Fan, Qi Hu, Xin Liu, Chunkit Chan, Duanyi Yao, Yuan Yao, and Yangqiu Song. 2024. PrivLM-Bench: A Multi-level Privacy Evaluation Benchmark for Language Models. In Proceedings of the 62nd Annual Meeting of the Association for Computational Li...
2024
-
[17]
Qinbin Li, Junyuan Hong, Chulin Xie, Jeffrey Tan, Rachel Xin, Junyi Hou, Xavier Yin, Zhun Wang, Dan Hendrycks, Zhangyang Wang, et al . 2024. LLM-PBE: Assessing Data Privacy in Large Language Models. Proceedings of the VLDB Endowment 17, 11 (2024), 3201–3214
2024
-
[18]
Yao Li, Alfred Kobsa, Bart P Knijnenburg, and MH Carolyn Nguyen. 2017. Cross- cultural privacy prediction. Proceedings on Privacy Enhancing Technologies (2017)
2017
-
[19]
Hannah Limerick, David Coyle, and James W Moore. 2014. The experience of agency in human-computer interactions: a review. Frontiers in human neuro- science 8 (2014), 643
2014
-
[20]
Lei Liu, Xiaoyan Yang, Yue Shen, Binbin Hu, Zhiqiang Zhang, Jinjie Gu, and Guannan Zhang. 2023. Think-in-Memory: Recalling and Post-thinking Enable LLMs with Long-Term Memory. CoRR abs/2311.08719 (2023). http://dblp.uni- trier.de/db/journals/corr/corr2311.html#abs-2311-08719
2023 arXiv
-
[21]
Nelson F Liu, Kevin Lin, John Hewitt, Ashwin Paranjape, Michele Bevilacqua, Fabio Petroni, and Percy Liang. 2024. Lost in the middle: How language models use long contexts. Transactions of the Association for Computational Linguistics 12 (2024), 157–173
2024
-
[22]
Rongjun Ma, Caterina Maidhof, Juan Carlos Carrillo, Janne Lindqvist, and Jose Such. 2025. Privacy Perceptions of Custom GPTs by Users and Creators. In Proceedings of the 2025 CHI Conference on Human Factors in Computing Systems . 1–18
2025
-
[23]
Ying Ma, Shiquan Zhang, Dongju Yang, Zhanna Sarsenbayeva, Jarrod Knibbe, and Jorge Goncalves. 2025. Raising Awareness of Location Information Vulnerabilities in Social Media Photos using LLMs. In Proceedings of the 2025 CHI Conference on Human Factors in Computing Systems . 1–14
2025
-
[24]
George R Milne, George Pettinico, Fatima M Hajjat, and Ereni Markos. 2017. Information sensitivity typology: Mapping the degree and type of risk consumers perceive in personal data sharing. Journal of Consumer Affairs 51, 1 (2017), 133–161
2017
-
[25]
Helen Nissenbaum. 2011. A contextual approach to privacy online. Daedalus 140, 4 (2011), 32–48
2011
-
[26]
Judith S Olson, Jonathan Grudin, and Eric Horvitz. 2005. A study of preferences for sharing and privacy. In CHI’05 extended abstracts on Human factors in computing systems. 1985–1988
2005
-
[27]
OpenAI. 2024. Memory and New Controls for ChatGPT. https://openai.com/ blog/memory-and-new-controls-for-chatgpt. Accessed: 2024-08-30
2024
-
[28]
Arielle Pardes. 2018. The Emotional Chatbots Are Here to Probe Our Feelings. Wired (oct 2018). https://www.wired.com/story/replika-open-source/
2018
-
[29]
Hanna Schneider, Florian Lachner, Malin Eiband, Ceenu George, Purvish Shah, Chinmay Parab, Anjali Kukreja, Heinrich Hussmann, and Andreas Butz. 2018. Privacy and personalization: the story of a cross-cultural field study. Interactions 25, 3 (2018), 52–55
2018
-
[30]
Yijia Shao, Tianshi Li, Weiyan Shi, Yanchen Liu, and Diyi Yang. [n. d.]. Priva- cyLens: Evaluating Privacy Norm Awareness of Language Models in Action. In The Thirty-eight Conference on Neural Information Processing Systems Datasets and Benchmarks Track
-
[31]
Freda Shi, Xinyun Chen, Kanishka Misra, Nathan Scales, David Dohan, Ed H Chi, Nathanael Schärli, and Denny Zhou. 2023. Large language models can be easily distracted by irrelevant context. In International Conference on Machine Learning . PMLR, 31210–31227
2023
-
[32]
Qingyue Wang, Liang Ding, Yanan Cao, Zhiliang Tian, Shi Wang, Dacheng Tao, and Li Guo. 2023. Recursively summarizing enables long-term dialogue memory in large language models. arXiv preprint arXiv:2308.15022 (2023)
2023 arXiv
-
[33]
Laura Weidinger, Jonathan Uesato, Maribeth Rauh, Conor Griffin, Po-Sen Huang, John Mellor, Amelia Glaese, Myra Cheng, Borja Balle, Atoosa Kasirzadeh, et al
-
[34]
Tianyu Wu, Shizhu He, Jingping Liu, Siqi Sun, Kang Liu, Qing-Long Han, and Yang Tang. 2023. A brief overview of ChatGPT: The history, status quo and potential future development. IEEE/CAA Journal of Automatica Sinica 10, 5 (2023), 1122–1136
2023
-
[35]
Yijia Xiao, Yiqiao Jin, Yushi Bai, Yue Wu, Xianjun Yang, Xiao Luo, Wenchao Yu, Xujiang Zhao, Yanchi Liu, Quanquan Gu, et al. 2024. Large Language Models Can Be Contextual Privacy Protection Learners. In Proceedings of the 2024 Conference on Empirical Methods in Natural Languag...
2024
-
[36]
Anran Xu, Zhongyi Zhou, Kakeru Miyazaki, Ryo Yoshikawa, Simo Hosio, and Koji Yatani. 2024. DIPA2: An Image Dataset with Cross-cultural Privacy Percep- tion Annotations. Proceedings of the ACM on Interactive, Mobile, Wearable and Ubiquitous Technologies 7, 4 (2024), 1–30
2024
-
[37]
In Proceedings of the 2022 ACM conference on fairness, accountability, and transparency
Taxonomy of risks posed by language models. In Proceedings of the 2022 ACM conference on fairness, accountability, and transparency . 214–229
2022
-
[38]
Xinchao Xu, Zhibin Gou, Wenquan Wu, Zheng-Yu Niu, Hua Wu, Haifeng Wang, and Shihang Wang. 2022. Long Time No See! Open-Domain Conversation with Long-Term Persona Memory
2022
-
[39]
Yaqing Yang, Tony W Li, and Haojian Jin. 2024. On the Feasibility of Predicting Users’ Privacy Concerns using Contextual Labels and Personal Preferences. In Proceedings of the 2024 CHI Conference on Human Factors in Computing Systems . 1–20
2024
-
[40]
Ryan Yen and Jian Zhao. 2024. Memolet: Reifying the Reuse of User-AI Conver- sational Memories. In Proceedings of the 37th Annual ACM Symposium on User Interface Software and Technology. 1–22
2024
-
[41]
J Xu. 2021. Beyond goldfish memory: Long-term open-domain conversation. arXiv preprint arXiv:2107.07567 (2021)
2021 arXiv
-
[42]
Bo Zhang and S Shyam Sundar. 2019. Proactive vs. reactive personalization: Can customization of privacy enhance user experience? International journal of human-computer studies 128 (2019), 86–99
2019
-
[43]
Shuning Zhang, Ying Ma, YongquanOwen’ Hu, Ting Dang, Hong Jia, Xin Yi, and Hewu Li. 2025. From Patient Burdens to User Agency: Designing for Real-Time Protection Support in Online Health Consultations. arXiv preprint arXiv:2508.00328 (2025)
2025 arXiv
-
[44]
Ghost of the past
Shuning Zhang, Lyumanshan Ye, Xin Yi, Jingyu Tang, Bo Shui, Haobin Xing, Pengfei Liu, and Hewu Li. 2024. " Ghost of the past": identifying and resolving privacy leakage from LLM’s memory through proactive user interaction. arXiv preprint arXiv:2410.14931 (2024)
2024 arXiv
-
[45]
Yangyang Yu, Haohang Li, Zhi Chen, Yuechen Jiang, Yang Li, Denghui Zhang, Rong Liu, Jordan W Suchow, and Khaldoun Khashanah. 2024. FinMem: A performance-enhanced LLM trading agent with layered memory and character design. In Proceedings of the AAAI Symposium Series , Vol. 3. 595–597
2024
-
[46]
Zhiping Zhang, Bingcan Guo, and Tianshi Li. 2024. Privacy Leakage Overshad- owed by Views of AI: A Study on Human Oversight of Privacy in Language Model Agent. arXiv preprint arXiv:2411.01344 (2024)
2024
-
[47]
It’s a Fair Game
Zhiping Zhang, Michelle Jia, Hao-Ping Lee, Bingsheng Yao, Sauvik Das, Ada Lerner, Dakuo Wang, and Tianshi Li. 2024. “It’s a Fair Game”, or Is It? Examining How Users Navigate Disclosure Risks and Benefits When Using LLM-Based Conversational Agents. In Proceedings of the CHI Co...
2024
-
[48]
Xiangyu Zhao, Longbiao Wang, and Jianwu Dang. 2022. Improving dialogue generation via proactively querying grounded knowledge. In ICASSP 2022-2022 IEEE International Conference on Acoustics, Speech and Signal Processing (ICASSP) . IEEE, 6577–6581
2022
-
[49]
Shuning Zhang, Xin Yi, Haobin Xing, Lyumanshan Ye, Yongquan Hu, and Hewu Li. 2024. Adanonymizer: Interactively Navigating and Balancing the Duality of Privacy and Output Performance in Human-LLM Interaction. arXiv preprint arXiv:2410.15044 (2024)
2024 arXiv
-
[50]
Jijie Zhou, Eryue Xu, Yaoyao Wu, and Tianshi Li. 2025. Rescriber: Smaller-LLM- Powered User-Led Data Minimization for LLM-Based Chatbots. In Proceedings of the 2025 CHI Conference on Human Factors in Computing Systems . 1–28
2025
-
[51]
AI is from the devil
Noé Zufferey, Sarah Abdelwahab Gaballah, Karola Marky, and Verena Zimmer- mann. 2025. “AI is from the devil. ” Behaviors and Concerns Toward Personal Data Sharing with LLM-based Conversational Agents. Proceedings on Privacy Enhancing Technologies 2025, 3 (2025), 5–28. A Ethica...
2025
-
[53]
Hanxun Zhong, Zhicheng Dou, Yutao Zhu, Hongjin Qian, and Ji-Rong Wen
-
[54]
arXiv preprint arXiv:2204.08128 (2022)
Less is more: Learning to refine dialogue history for personalized dialogue generation. arXiv preprint arXiv:2204.08128 (2022)
2022 arXiv
-
[2020]
In Chatbot Research and Design: Third International Workshop, CONVERSATIONS 2019, Amsterdam, The Nether- lands, November 19–20, 2019, Revised Selected Papers 3
Privacy concerns in chatbot interactions. In Chatbot Research and Design: Third International Workshop, CONVERSATIONS 2019, Amsterdam, The Nether- lands, November 19–20, 2019, Revised Selected Papers 3 . Springer, 34–48
2019
-
[2022]
In Findings of the Association for Computational Linguistics: EMNLP 2022
Keep Me Updated! Memory Management in Long-term Conversations. In Findings of the Association for Computational Linguistics: EMNLP 2022. 3769–3787
2022
-
[2023]
InAdjunct Proceedings of the 36th Annual ACM Symposium on User Interface Software and Technology (San Francisco, CA, USA) (UIST ’23 Adjunct)
Memory Sandbox: Transparent and Interactive Memory Management for Conversational Agents. InAdjunct Proceedings of the 36th Annual ACM Symposium on User Interface Software and Technology (San Francisco, CA, USA) (UIST ’23 Adjunct). Association for Computing Machinery, New York,...
Reviewed August 5, 2026 · model on record in the stance chip above.
Discussion (0). Sign in to comment.