cs.CRSep 28, 2026

"Nothing to See Here'': Unintended Disclosure through Revision Traces of LLM Deliverables

Authors: Yage Zhang, Yukun Jiang, Yang Zhang

Organizations: CISPA Helmholtz Center for Information Security

Abstract

Large language model (LLM) assistants increasingly help users draft content for third-party recipients. During private drafting, the user or the model may introduce an item and later remove or replace it. The model may remove the item from the intended content but reveal it again when stating the edit. We call such statements revision traces. For example, after a user removes the password before sharing a configuration file, the model may delete it but leave a comment saying, "Removed the password 'No****4!' as requested." A third-party recipient who sees only the delivered file can therefore recover the withdrawn password from the comment. In an in-the-wild analysis of three public conversation corpora, we identify 26,753 revision requests, of which 2,363 (8.8%) leave revision traces. We study them in greater depth under controlled conditions by introducing RevLeakBench, a benchmark of 100 tasks across five scenarios with a conversation track and an agent track. We measure trace occurrence, withdrawn-item recovery, trace position, and required-content retention. Across six models, about half of the deliverables in both tracks state the edit after a revocation, and a reader that sees only the deliverable can recover the withdrawn item from about 13% of them. Telling the model that its entire reply will be forwarded to the recipient still leaves revision traces in 36.4% of the deliverables. We compare prompt defenses and a delivery boundary, and propose an output-side filter that sharply reduces recovery with little loss of required content. We believe our work can benefit efforts to understand and mitigate unintended disclosure in LLM interactions.

Figures & tables

Appendix figures & tables30 assets

Supplementary material from the paper’s appendix.

Appendix

Explore similar work

CardsList
  1. Stealing Reasoning Traces from Proprietary LLM APIs

    Aug 10, 2026Alexander Panfilov, David Schmotz, Ilia Shumailov +5LLM Reasoning StrategiesReasoning Traces

  2. PrivDrift: Auditing User-Secret Leakage Under Topic Drift in Active LLM Conversations

    Sep 24, 2026Luciano MaldonadoData LeakageDisclosures

  3. Auditable Release Control for Pedagogical Leakage in LLM Tutors

    Aug 1, 2026Nizam KadirData LeakageRelease