Sensitive Information Leakage from Tool-Call Traces
Jihyung Kook ⋅ Soomin Kim ⋅ Purna Chandra Sekhar Vakudavathu
Abstract
AI agents increasingly use external tools in sensitive domains such as healthcare. While existing privacy research focuses on protecting prompts and tool payloads, tool invocation logs are often treated as harmless. We study a zero-payload setting in which an adversary observes only the names of invoked tools. Using traces from a simulated healthcare agent, we evaluate whether LLMs and machine learning models can infer treatment complexity, condition deterioration, and readmission risk. Our results show that tool names and usage patterns contain predictive information about these attributes. In the LLM and MLP experiments, an order-agnostic $\textit{Bag-of-Tools}$ performs similarly to or better than order-aware representations, indicating that tool selection and frequency can leak sensitive information without invocation order. These findings show that protecting tool payloads alone is insufficient and that tool invocation logs should also be treated as sensitive.
Chat is not available.
Successful Page Load