{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,13]],"date-time":"2026-04-13T04:45:01Z","timestamp":1776055501253,"version":"3.50.1"},"publisher-location":"New York, NY, USA","reference-count":38,"publisher":"ACM","funder":[{"name":"National Research Foundation of Korea (NRF)","award":["2710004669"],"award-info":[{"award-number":["2710004669"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2026,4,13]]},"DOI":"10.1145\/3772363.3798860","type":"proceedings-article","created":{"date-parts":[[2026,4,13]],"date-time":"2026-04-13T01:55:28Z","timestamp":1776045328000},"page":"1-10","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":0,"title":["Your Permission Leaks My Data: Second-Hand Privacy Harms in LLM Agents"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0009-0001-9906-7461","authenticated-orcid":false,"given":"Minje","family":"Kim","sequence":"first","affiliation":[{"name":"Yonsei University, Seoul, Republic of Korea"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-3291-5753","authenticated-orcid":false,"given":"Keeheon","family":"Lee","sequence":"additional","affiliation":[{"name":"Yonsei University, Seoul, Republic of Korea"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2026,4,13]]},"reference":[{"key":"e_1_3_3_2_2_2","unstructured":"Anthropic. 2026. Enabling and Using the Microsoft 365 Connector. https:\/\/support.claude.com\/en\/articles\/12542951-enabling-and-using-the-microsoft-365-connector. Accessed: 2026-01-22."},{"key":"e_1_3_3_2_3_2","doi-asserted-by":"crossref","unstructured":"Jin Chen Zheng Liu Xu Huang Chenwang Wu Qi Liu Gangwei Jiang Yuanhao Pu Yuxuan Lei Xiaolong Chen Xingmei Wang et\u00a0al. 2024. When large language models meet personalization: Perspectives of challenges and opportunities. World Wide Web 27 4 (2024) 42.","DOI":"10.1007\/s11280-024-01276-1"},{"key":"e_1_3_3_2_4_2","doi-asserted-by":"crossref","unstructured":"Andrea Cuadra Justine Breuch Samantha Estrada David Ihim Isabelle Hung Derek Askaryar Marwan Hassanien Kristen\u00a0L Fessele and James\u00a0A Landay. 2024. Digital forms for all: A holistic multimodal large language model agent for health data entry. Proceedings of the ACM on Interactive Mobile Wearable and Ubiquitous Technologies 8 2 (2024) 1\u201339.","DOI":"10.1145\/3659624"},{"key":"e_1_3_3_2_5_2","doi-asserted-by":"publisher","DOI":"10.1145\/2335356.2335360"},{"key":"e_1_3_3_2_6_2","doi-asserted-by":"publisher","DOI":"10.1145\/3706599.3720284"},{"key":"e_1_3_3_2_7_2","doi-asserted-by":"crossref","unstructured":"Amir Gandomi and Murtaza Haider. 2015. Beyond the hype: Big data concepts methods and analytics. International Journal of Information Management (2015).","DOI":"10.1016\/j.ijinfomgt.2014.10.007"},{"key":"e_1_3_3_2_8_2","unstructured":"Google. 2025. Connect the Google Workspace app to Gemini Apps. https:\/\/support.google.com\/gemini\/answer\/15229592?hl=en. Accessed: 2026-01-22."},{"key":"e_1_3_3_2_9_2","doi-asserted-by":"publisher","DOI":"10.1109\/CCWC62904.2025.10903878"},{"key":"e_1_3_3_2_10_2","unstructured":"Guy Hacohen et\u00a0al. 2024. The Limits of Privacy in the Age of LLM Agents. arXiv preprint arXiv:https:\/\/arXiv.org\/abs\/2402.01234 (2024)."},{"key":"e_1_3_3_2_11_2","volume-title":"Proceedings of the 9th Machine Learning for Healthcare Conference","author":"Hao Yijie","year":"2024","unstructured":"Yijie Hao, Huan He, and Joyce\u00a0C Ho. 2024. Llmsyn: Generating synthetic electronic health records without patient-level data. In Proceedings of the 9th Machine Learning for Healthcare Conference."},{"key":"e_1_3_3_2_12_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-40203-6_38"},{"key":"e_1_3_3_2_13_2","doi-asserted-by":"crossref","unstructured":"Mathias Humbert et\u00a0al. 2019. A survey on interdependent privacy: Mechanisms and open challenges. ACM Computing Surveys (CSUR) 52 6 (2019) 1\u201340.","DOI":"10.1145\/3360498"},{"key":"e_1_3_3_2_14_2","volume-title":"WWW","author":"Jia Jinyuan","year":"2017","unstructured":"Jinyuan Jia et\u00a0al. 2017. AttriInfer: Inferring user attributes in online social networks. In WWW."},{"key":"e_1_3_3_2_15_2","unstructured":"Alexey Kurakin Natalia Ponomareva Umar Syed Liam MacDermed and Andreas Terzis. 2023. Harnessing large-language models to generate private synthetic text. arXiv preprint arXiv:https:\/\/arXiv.org\/abs\/2306.01684 (2023)."},{"key":"e_1_3_3_2_16_2","unstructured":"Yuanchun Li Hao Wen Weijun Wang Xiangyu Li Yizhen Yuan Guohong Liu Jiacheng Liu Wenxing Xu Xiang Wang Yi Sun et\u00a0al. 2024. Personal llm agents: Insights and survey about the capability efficiency and security. arXiv preprint arXiv:https:\/\/arXiv.org\/abs\/2401.05459 (2024)."},{"key":"e_1_3_3_2_17_2","unstructured":"Deirdre\u00a0K Mulligan et\u00a0al. 2016. Privacy is an essentially contested concept. Philosophical Transactions of the Royal Society A (2016)."},{"key":"e_1_3_3_2_18_2","unstructured":"Md\u00a0Mahadi\u00a0Hasan Nahid and Sadid\u00a0Bin Hasan. 2024. Safesynthdp: Leveraging large language models for privacy-preserving synthetic data generation using differential privacy. arXiv preprint arXiv:https:\/\/arXiv.org\/abs\/2412.20641 (2024)."},{"key":"e_1_3_3_2_19_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2008.33"},{"key":"e_1_3_3_2_20_2","doi-asserted-by":"publisher","DOI":"10.1145\/1743546.1743558"},{"key":"e_1_3_3_2_21_2","unstructured":"Helen Nissenbaum. 2004. Privacy as contextual integrity. Washington Law Review (2004)."},{"key":"e_1_3_3_2_22_2","doi-asserted-by":"crossref","unstructured":"Helen Nissenbaum. 2019. Contextual integrity up and down the data food chain. Theoretical Inquiries in Law (2019).","DOI":"10.1515\/til-2019-0008"},{"key":"e_1_3_3_2_23_2","doi-asserted-by":"crossref","unstructured":"Rodrigo Novelo Rodrigo\u00a0Rocha Silva and Jorge Bernardino. 2025. A Literature Review of Personalized Large Language Models for Email Generation and Automation. Future Internet 17 12 (2025) 536.","DOI":"10.3390\/fi17120536"},{"key":"e_1_3_3_2_24_2","unstructured":"OpenAI. 2024. Hello GPT-4o. https:\/\/openai.com\/index\/hello-gpt-4o\/ Accessed: 2026-01-20."},{"key":"e_1_3_3_2_25_2","doi-asserted-by":"publisher","DOI":"10.1609\/icaps.v34i1.31503"},{"key":"e_1_3_3_2_26_2","doi-asserted-by":"crossref","unstructured":"Lei Pan et\u00a0al. 2024. A survey on large language model-based autonomous agents. Frontiers of Computer Science 18 2 (2024) 1\u201326.","DOI":"10.1007\/s11704-024-40231-1"},{"key":"e_1_3_3_2_27_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP40000.2020.00095"},{"key":"e_1_3_3_2_28_2","volume-title":"Proceedings of the 2016 ACM International Joint Conference on Pervasive and Ubiquitous Computing","author":"Pu Yifang","year":"2016","unstructured":"Yifang Pu and Jens Grossklags. 2016. Interdependent privacy: Let me share your data. In Proceedings of the 2016 ACM International Joint Conference on Pervasive and Ubiquitous Computing."},{"key":"e_1_3_3_2_29_2","doi-asserted-by":"crossref","unstructured":"Alexandra Ralevski Nadaa Taiyab Michael Nossal Lindsay Mico Samantha Piekos and Jennifer Hadlock. 2024. Using large language models to abstract complex social determinants of health from original and deidentified medical notes: development and validation study. Journal of medical Internet research 26 (2024) e63445.","DOI":"10.2196\/63445"},{"key":"e_1_3_3_2_30_2","unstructured":"Maria Rigaki and Sebastian Garcia. 2020. A survey of privacy attacks in machine learning. arXiv (2020)."},{"key":"e_1_3_3_2_31_2","volume-title":"SOUPS","author":"Schaub Florian","year":"2015","unstructured":"Florian Schaub et\u00a0al. 2015. A design space for effective privacy notices. In SOUPS."},{"key":"e_1_3_3_2_32_2","unstructured":"Timo Schick et\u00a0al. 2023. Toolformer: Language models can teach themselves to use tools. arXiv preprint arXiv:https:\/\/arXiv.org\/abs\/2302.04761 (2023)."},{"key":"e_1_3_3_2_33_2","volume-title":"ACM CCS","author":"Shokri Reza","year":"2015","unstructured":"Reza Shokri and Vitaly Shmatikov. 2015. Privacy-preserving deep learning. In ACM CCS."},{"key":"e_1_3_3_2_34_2","volume-title":"ICLR","author":"Staab Robin","year":"2024","unstructured":"Robin Staab et\u00a0al. 2024. Beyond Memorization: Violating Privacy via Inference with Large Language Models. In ICLR."},{"key":"e_1_3_3_2_35_2","doi-asserted-by":"publisher","DOI":"10.1109\/CAI59869.2024.00152"},{"key":"e_1_3_3_2_36_2","doi-asserted-by":"crossref","unstructured":"Salome Viljoen. 2021. A Relational Theory of Data Governance. Yale Law Journal 131 (2021).","DOI":"10.2139\/ssrn.3727562"},{"key":"e_1_3_3_2_37_2","unstructured":"Oshadha Wijerathne Amandi Nimasha Dushan Fernando Nisansa de Silva and Srinath Perera. 2025. ScheduleMe: Multi-Agent Calendar Assistant. arXiv preprint arXiv:https:\/\/arXiv.org\/abs\/2509.25693 (2025)."},{"key":"e_1_3_3_2_38_2","unstructured":"Windows Insider Blog. 2025. Copilot on Windows: Connectors and Document Creation. https:\/\/blogs.windows.com\/windows-insider\/2025\/10\/09\/copilot-on-windows-connectors-and-document-creation\/. Accessed: 2026-01-22."},{"key":"e_1_3_3_2_39_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICoCSETI63724.2025.11020503"}],"event":{"name":"CHI EA '26: Extended Abstracts of the 2026 CHI Conference on Human Factors in Computing Systems","location":"Barcelona , Spain","acronym":"CHI EA '26","sponsor":["SIGCHI ACM Special Interest Group on Computer-Human Interaction"]},"container-title":["Proceedings of the Extended Abstracts of the 2026 CHI Conference on Human Factors in Computing Systems"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3772363.3798860","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,4,13]],"date-time":"2026-04-13T03:58:05Z","timestamp":1776052685000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3772363.3798860"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,4,13]]},"references-count":38,"alternative-id":["10.1145\/3772363.3798860","10.1145\/3772363"],"URL":"https:\/\/doi.org\/10.1145\/3772363.3798860","relation":{},"subject":[],"published":{"date-parts":[[2026,4,13]]},"assertion":[{"value":"2026-04-13","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}