cs.CRSep 29, 2026

Privacy in Personalized AI Is a System Property, Not Just a Model Property

Authors: Guillaume Salha-Galvan, Jiaying Xu

Organizations: SJTU Paris Elite Institute of Technology · Kibo Ryoku Research

Abstract

In personalized AI applications, such as conversational assistants and recommender systems, users interact not with models in isolation but with broader systems that access, infer, and reuse user information across components and over time. While such use of user information is integral to personalization, it also raises important privacy questions. In this paper, we argue that individual model- or component-level analyses may not capture all privacy risks arising in such systems, motivating a system-level perspective on privacy. We distinguish and analyze four interconnected privacy-risk channels in personalized AI, and subsequently propose four requirements for system-level privacy evaluation, covering interaction trajectories, internal information flows, indirect leakage, and the privacy-utility trade-off. We argue for their systematic incorporation into privacy audits of personalized AI.

Explore similar work

CardsList
  1. Personalization Meets Safety:Mechanisms,Risks,and Mitigations in Personalized LLMs

    Jun 8, 2026Yanyan Luo, Xue Han, Ruiqiao Bai +10Large Language Model PersonalizationLarge Language Model Safety

  2. PrivacySkills: How Privacy Guidance Shapes Source Selection in LLM Agents

    Sep 28, 2026Lucas Biechy, Cédric Eichler, Héber H. Arcolezi +1PrivacyLarge Language Model Agents