PaperScope
LIVE · 2026-10-01 05:40 UTC

Privacy in Personalized AI Is a System Property, Not Just a Model Property

Guillaume Salha-Galvan, Jiaying Xu

Latestcs.CLcs.LGcs.AIcs.CV
arXiv ID
2609.38289 v1
Category
Submitted
2026-09-29

Abstract

In personalized AI applications, such as conversational assistants and recommender systems, users interact not with models in isolation but with broader systems that access, infer, and reuse user information across components and over time. While such use of user information is integral to personalization, it also raises important privacy questions. In this paper, we argue that individual model- or component-level analyses may not capture all privacy risks arising in such systems, motivating a system-level perspective on privacy. We distinguish and analyze four interconnected privacy-risk channels in personalized AI, and subsequently propose four requirements for system-level privacy evaluation, covering interaction trajectories, internal information flows, indirect leakage, and the privacy-utility trade-off. We argue for their systematic incorporation into privacy audits of personalized AI.

Comment: NeurIPS 2026 Workshop on Privacy in the Era of Large Opaque Models

arXiv abs page · PDF · same-day batch