{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2024:NDYOG3T7UP4YLV3ERYPNFVPFIB","short_pith_number":"pith:NDYOG3T7","schema_version":"1.0","canonical_sha256":"68f0e36e7fa3f985d7648e1ed2d5e54063109752268936b0b245a1791e69b3b2","source":{"kind":"arxiv","id":"2405.05175","version":2},"attestation_state":"computed","paper":{"title":"AirGapAgent: Protecting Privacy-Conscious Conversational Agents","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.CL","cs.LG"],"primary_cat":"cs.CR","authors_text":"Borja Balle, Daniel Ramage, Eugene Bagdasarian, Marco Gruteser, Peter Kairouz, Ren Yi, Sahra Ghalebikesabi, Sewoong Oh","submitted_at":"2024-05-08T16:12:45Z","abstract_excerpt":"The growing use of large language model (LLM)-based conversational agents to manage sensitive user data raises significant privacy concerns. While these agents excel at understanding and acting on context, this capability can be exploited by malicious actors. We introduce a novel threat model where adversarial third-party apps manipulate the context of interaction to trick LLM-based agents into revealing private information not relevant to the task at hand.\n  Grounded in the framework of contextual integrity, we introduce AirGapAgent, a privacy-conscious agent designed to prevent unintended da"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2405.05175","kind":"arxiv","version":2},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2024-05-08T16:12:45Z","cross_cats_sorted":["cs.CL","cs.LG"],"title_canon_sha256":"cf7d187714f6f01ae871a39fa4fa2684c718d8ff6983752d76288cab0aa871bd","abstract_canon_sha256":"28ef41cecfc93ddfa82eff44593c11939ed0876dfc6b98bde2670eeaad2a9a2a"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T09:08:47.990028Z","signature_b64":"SBL7inLRYqVKFzJUwonDa2gOupwDrORPrP7WerbZ7+0/S7gqAomvfH0EFrlPXYq3NXJoif6FqEirXUvC2hqVBw==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"68f0e36e7fa3f985d7648e1ed2d5e54063109752268936b0b245a1791e69b3b2","last_reissued_at":"2026-07-05T09:08:47.989450Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T09:08:47.989450Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"AirGapAgent: Protecting Privacy-Conscious Conversational Agents","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.CL","cs.LG"],"primary_cat":"cs.CR","authors_text":"Borja Balle, Daniel Ramage, Eugene Bagdasarian, Marco Gruteser, Peter Kairouz, Ren Yi, Sahra Ghalebikesabi, Sewoong Oh","submitted_at":"2024-05-08T16:12:45Z","abstract_excerpt":"The growing use of large language model (LLM)-based conversational agents to manage sensitive user data raises significant privacy concerns. While these agents excel at understanding and acting on context, this capability can be exploited by malicious actors. We introduce a novel threat model where adversarial third-party apps manipulate the context of interaction to trick LLM-based agents into revealing private information not relevant to the task at hand.\n  Grounded in the framework of contextual integrity, we introduce AirGapAgent, a privacy-conscious agent designed to prevent unintended da"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2405.05175","kind":"arxiv","version":2},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2405.05175/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2405.05175","created_at":"2026-07-05T09:08:47.989513+00:00"},{"alias_kind":"arxiv_version","alias_value":"2405.05175v2","created_at":"2026-07-05T09:08:47.989513+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2405.05175","created_at":"2026-07-05T09:08:47.989513+00:00"},{"alias_kind":"pith_short_12","alias_value":"NDYOG3T7UP4Y","created_at":"2026-07-05T09:08:47.989513+00:00"},{"alias_kind":"pith_short_16","alias_value":"NDYOG3T7UP4YLV3E","created_at":"2026-07-05T09:08:47.989513+00:00"},{"alias_kind":"pith_short_8","alias_value":"NDYOG3T7","created_at":"2026-07-05T09:08:47.989513+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":8,"internal_anchor_count":0,"sample":[{"citing_arxiv_id":"2606.26627","citing_title":"Agents That Know Too Much: A Data-Centric Survey of Privacy in LLM Agents","ref_index":11,"is_internal_anchor":false},{"citing_arxiv_id":"2605.10907","citing_title":"Engineering Robustness into Personal Agents with the AI Workflow Store","ref_index":9,"is_internal_anchor":false},{"citing_arxiv_id":"2606.30383","citing_title":"Whose Side Is Your Agent On? Multi-Party Principal Loyalty in LLM Agents","ref_index":7,"is_internal_anchor":false},{"citing_arxiv_id":"2509.21465","citing_title":"Talking Trees: Reasoning-Assisted Induction of Decision Trees for Tabular Data","ref_index":43,"is_internal_anchor":false},{"citing_arxiv_id":"2508.10880","citing_title":"Searching for Privacy Risks in LLM Agents via Simulation","ref_index":1,"is_internal_anchor":false},{"citing_arxiv_id":"2605.10907","citing_title":"Engineering Robustness into Personal Agents with the AI Workflow Store","ref_index":9,"is_internal_anchor":false},{"citing_arxiv_id":"2605.10907","citing_title":"Engineering Robustness into Personal Agents with the AI Workflow Store","ref_index":9,"is_internal_anchor":false},{"citing_arxiv_id":"2604.19657","citing_title":"An AI Agent Execution Environment to Safeguard User Data","ref_index":5,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/NDYOG3T7UP4YLV3ERYPNFVPFIB","json":"https://pith.science/pith/NDYOG3T7UP4YLV3ERYPNFVPFIB.json","graph_json":"https://pith.science/api/pith-number/NDYOG3T7UP4YLV3ERYPNFVPFIB/graph.json","events_json":"https://pith.science/api/pith-number/NDYOG3T7UP4YLV3ERYPNFVPFIB/events.json","paper":"https://pith.science/paper/NDYOG3T7"},"agent_actions":{"view_html":"https://pith.science/pith/NDYOG3T7UP4YLV3ERYPNFVPFIB","download_json":"https://pith.science/pith/NDYOG3T7UP4YLV3ERYPNFVPFIB.json","view_paper":"https://pith.science/paper/NDYOG3T7","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2405.05175&json=true","fetch_graph":"https://pith.science/api/pith-number/NDYOG3T7UP4YLV3ERYPNFVPFIB/graph.json","fetch_events":"https://pith.science/api/pith-number/NDYOG3T7UP4YLV3ERYPNFVPFIB/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/NDYOG3T7UP4YLV3ERYPNFVPFIB/action/timestamp_anchor","attest_storage":"https://pith.science/pith/NDYOG3T7UP4YLV3ERYPNFVPFIB/action/storage_attestation","attest_author":"https://pith.science/pith/NDYOG3T7UP4YLV3ERYPNFVPFIB/action/author_attestation","sign_citation":"https://pith.science/pith/NDYOG3T7UP4YLV3ERYPNFVPFIB/action/citation_signature","submit_replication":"https://pith.science/pith/NDYOG3T7UP4YLV3ERYPNFVPFIB/action/replication_record"}},"created_at":"2026-07-05T09:08:47.989513+00:00","updated_at":"2026-07-05T09:08:47.989513+00:00"}