100+ free AI courses from Google, Microsoft, Anthropic and NVIDIA, no paywalls, ever. Click the chat button below.

MosaicLeaks: Can your research agent keep a secret?

  • Deep research agents frequently leak private enterprise data through innocuous-looking external web queries via the mosaic effect.
  • The MosaicLeaks dataset comprises 1,001 multi-hop research chains designed to test privacy vulnerabilities across local and public information sources.
  • Privacy-Aware Deep Research (PA-DR) training increases strict chain success rates from 48.7% to 58.7% while reducing full-information leakage from 34.0% to 9.9%.
  • Agents often fail to isolate sensitive internal context, inadvertently exposing proprietary metrics to external observers.

Automated research agents require new privacy-aware training protocols to prevent the accidental exposure of sensitive internal data through external search queries.

Why this matters right now

Ignoring the mosaic effect allows external observers to reconstruct confidential business strategies by aggregating fragmented search logs. When agents interleave private documents with public web tools, they often inadvertently broadcast internal milestones or security disclosures. Organizations that successfully implement privacy-aware training can deploy agents for complex competitive analysis without compromising their proprietary data. However, these models still face limitations in balancing high-performance reasoning with the strict obfuscation of sensitive query parameters.

How this technology has evolved

Alexander Gurung and Rafael Pardinas of ServiceNow developed the MosaicLeaks framework to quantify how research agents leak information through outbound traffic. The team introduced Privacy-Aware Deep Research (PA-DR) training to mitigate these risks, demonstrating that performance-only training actually exacerbates leakage. While PA-DR improves reasoning accuracy, the approach remains constrained by the inherent difficulty of sanitizing queries that rely on private context for downstream tasks.

MetricStandard TrainingPA-DR Training
Strict Chain Success48.7%58.7%
Full-Information Leakage34.0%9.9%

What this means for your roadmap

This week

  • Audit current research agent workflows to identify endpoints where internal documents are accessed alongside external search tools.
  • Review outbound traffic logs for recurring patterns that could reveal specific project goals or proprietary metrics.

This quarter

  • Implement privacy-aware training constraints to ensure agent queries do not carry forward sensitive bridge entities.
  • Establish a red-teaming protocol to test whether agents leak internal milestones during routine market research tasks.

This year

  • Transition to agent architectures that utilize local-only processing for sensitive data analysis.
  • Standardize privacy-leakage benchmarks for all internal AI tools to ensure compliance with data protection requirements.

Sources

  1. Hugging Face: MosaicLeaks: Can your research agent keep a secret?

Was this article helpful?

Your rating is stored anonymously and used to improve article quality. No personal data is required. See our Privacy Policy.

AI-assisted content: This article, MosaicLeaks: Can your research agent keep a secret?, was drafted using AI assistance (google/gemini-3.1-flash-lite-preview) on 21 June 2026 and reviewed by the BytesAI editorial team before publication. Verified sources: Hugging Face: MosaicLeaks: Can your research agent keep a secret?. Learn about our editorial process.

Know a researcher or engineer working on alignment?

Forward this briefing — AI generates platform-optimised copy for you.