[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-83696-en":3,"doc-seo-83696-105":30,"detail-sidebar-cat-0-en-105":91},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":21,"is_downloadable":21,"audit_status":21,"page_count":22,"language":23,"language_code":24,"site_id":25,"html_lang":24,"table_of_contents":26,"faqs":27,"seo_title":13,"seo_description":14,"update_tm":28,"read_time":29},83696,4810365810221,"Aurora","https://ap-avatar.wpscdn.com/davatar_155a257f0dc6eb9ab79c44ca47cae57d",8,"Research & Report","Privacy-Utility Optimized Prompt Obfuscation With PromptPET","Privacy protection is critical in AI chatbot interactions because users can reveal sensitive information, which chatbots may use to profile users. This work introduces a user-side prompt transformation that obfuscates sensitive content while retaining enough signal to generate useful responses. Four obfuscation actions are considered—redaction, abstraction, replacement, and a noising/denoising scheme—optimized and evaluated via privacy-utility tradeoffs. PromptPET, an LLM-based reinforcement-learning-inspired agent, selects the best action per sensitive fragment and matches optimal single-action tradeoffs while outperforming prior state of the art on a real chat dataset.","PromptPET: Privacy-Utility Optimized Prompt Obfuscation  \nKe Yang  \nUniversity of California, Irvine Irvine, CA, USA[ke.yang@uci.edu](ke.yang@uci.edu)  \nOlivia Figueira  \nUniversity of California, Irvine Irvine, CA, USA [olivia.f@uci.edu](olivia.f@uci.edu)  \nUmar Iqbal  \nWashington University in St. Louis St. Louis, MO, USA [umar.iqbal@wustl.edu](umar.iqbal@wustl.edu)  \nAthina Markopoulou  \nUniversity of California, Irvine Irvine, CA, USA [athina@uci.edu](athina@uci.edu)  \narXiv :2607 .02932v 1 [ cs .CR] 3 Jul 2026  \nAbstract  \nPrivacy is an important challenge when users interact with AI chatbots, since users may share sensitive information, explicitly or implicitly, and AI chatbots can use this information for user profiling. In this paper, we aim to protect users’ privacy via a userside mechanism that transforms sensitive information in a user’s prompt, while preserving enough information to elicit a useful response from the chatbot. This approach faces an inherent tradeoff between protecting privacy (i.e., avoiding profiling) and preserving utility (i.e., getting personalized and task-specific responses) . To that end, we consider, evaluate, and compare four different obfuscation actions, namely redaction, abstraction, replacement, anda novel noising/denoising scheme that we introduce. Additional novel insights include: utilizing a data type taxonomy to both identify and obfuscate sensitive information and explicitly taking into account the utility of chat responses in making the obfuscation decision. First, we systematically optimize and evaluate each obfuscation action independently in terms of the privacy-utility tradeoff it achieves. Second, we propose PromptPET, an LLM-based agent that selects the best obfuscation action for each sensitive part of the prompt, using a reinforcement-learning inspired rule optimizer, applied for the first time in this context. Using a real-world chat dataset, we show that PromptPET matches the best privacy-utility tradeoff attainable by any single obfuscation action and significantly outperforms prior state-of-the-art approaches.  \n1 Introduction  \nAI agents are rapidly becoming an everyday computing interface, with platforms such as ChatGPT [49], Gemini [21], and Claude [4] collectively serving over one billion users [64] . Users interact with these systems for both personal and professional tasks, such as drafting work documents, planning travel, managing finances, and even seeking medical [75] or legal advice [37] . Unlike conventional computing systems, users interface with AI agents through openended natural language, often describing their goals, constraints, preferences, and circumstances in detail. LLM-based agents, in turn, produce personalized, context-aware responses that are explicitly shaped by the information users provide [41] . This shift in the interaction paradigm encourages users to disclose richer and more sensitive information than they would in a search box, including details about their employment, health, relationships, financial status [41, 66], etc.  \nFigure 1: PromptPET Overview. A user interacts with an AI agent through a conversational interface. PromptPETsits between the user and the online AI agent, obfuscating sensitive parts of the user prompt (query) so that it subverts user profiling by the provider. See Figure 2 for details.  \nUnfortunately, this paradigm shift also introduces substantial and still poorly understood privacy and security risks. As AI agents rely on rich contextual input to provide useful responses, users may disclose sensitive personal information without fully understanding how that information is collected, retained, reused, or shared [27, 66] . In addition to the usual data collection and tracking practices in interactions with all online services, there are unique challenges for user privacy in interactions specifically with AI agents. First, the sensitivity of personal information that users reveal directly to AI agents, is way hig","cbCaiveNP4Ytiew5","https://ap.wps.com/l/cbCaiveNP4Ytiew5","pdf",1800694,4,1,16,"English","en",105,"# Abstract\n# Introduction\n## Problem and privacy risks\n## Prompt-side privacy control\n## Related work and research gap\n# Methods and contributions","[{\"question\":\"What privacy problem does PromptPET address in AI chatbot interactions?\",\"answer\":\"It addresses the risk that sensitive information in a user’s prompt can be used by chatbots to profile users, even when that information is provided implicitly or explicitly.\"},{\"question\":\"How does PromptPET protect privacy while maintaining response usefulness?\",\"answer\":\"It transforms sensitive parts of the user prompt on the user side, so the chatbot receives obfuscated content while still preserving enough information to elicit useful, task-relevant responses.\"},{\"question\":\"What kinds of obfuscation actions does the paper compare?\",\"answer\":\"The paper considers and evaluates four actions: redaction, abstraction, replacement, and a novel noising/denoising scheme.\"}]",1784189801,40,{"code":4,"msg":31,"data":32},"ok",{"site_id":25,"language":24,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":86,"head_meta":88,"extra_data":90,"updated_unix":28},"privacy-utility-optimized-prompt-obfuscation-with-promptpet","",{"@graph":36,"@context":85},[37,53,68],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":21},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":50},"https://docshare.wps.com/document/research-report/",3,{"item":52,"name":13,"@type":43,"position":20},"https://docshare.wps.com/document/privacy-utility-optimized-prompt-obfuscation-with-promptpet/83696/",{"url":52,"name":13,"@type":54,"author":55,"headline":13,"publisher":57,"fileFormat":60,"inLanguage":24,"description":14,"dateModified":61,"datePublished":62,"encodingFormat":60,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":56},"Person",{"url":41,"name":58,"@type":59},"DocShare","Organization","application/pdf","2026-07-25","2026-07-16",true,{"@type":65,"interactionType":66,"userInteractionCount":20},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81],{"name":72,"@type":73,"acceptedAnswer":74},"What privacy problem does PromptPET address in AI chatbot interactions?","Question",{"text":75,"@type":76},"It addresses the risk that sensitive information in a user’s prompt can be used by chatbots to profile users, even when that information is provided implicitly or explicitly.","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"How does PromptPET protect privacy while maintaining response usefulness?",{"text":80,"@type":76},"It transforms sensitive parts of the user prompt on the user side, so the chatbot receives obfuscated content while still preserving enough information to elicit useful, task-relevant responses.",{"name":82,"@type":73,"acceptedAnswer":83},"What kinds of obfuscation actions does the paper compare?",{"text":84,"@type":76},"The paper considers and evaluates four actions: redaction, abstraction, replacement, and a novel noising/denoising scheme.","https://schema.org",{"og:url":52,"og:type":87,"og:title":13,"og:site_name":58,"og:description":14},"article",{"robots":89,"canonical":52},"index,follow",{"doc_id":7,"site_id":25},{"code":4,"msg":5,"data":92},[93,97,101,105,110,115,119,122,127,130,134],{"id":21,"doc_module":4,"doc_module_name":46,"category_name":94,"show_sort_weight":95,"slug":96},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":98,"show_sort_weight":99,"slug":100},"Literature",80,"literature",{"id":20,"doc_module":4,"doc_module_name":46,"category_name":102,"show_sort_weight":103,"slug":104},"Exam",70,"exam",{"id":106,"doc_module":4,"doc_module_name":46,"category_name":107,"show_sort_weight":108,"slug":109},5,"Comic",60,"comic",{"id":111,"doc_module":4,"doc_module_name":46,"category_name":112,"show_sort_weight":113,"slug":114},6,"Technology",50,"technology",{"id":116,"doc_module":4,"doc_module_name":46,"category_name":117,"show_sort_weight":29,"slug":118},7,"Healthcare","healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":120,"slug":121},30,"research-report",{"id":123,"doc_module":4,"doc_module_name":46,"category_name":124,"show_sort_weight":125,"slug":126},9,"Religion & Spirituality",20,"religion-spirituality",{"id":125,"doc_module":4,"doc_module_name":46,"category_name":128,"show_sort_weight":125,"slug":129},"World Cup","world-cup",{"id":131,"doc_module":4,"doc_module_name":46,"category_name":132,"show_sort_weight":131,"slug":133},10,"Lifestyle","lifestyle",{"id":135,"doc_module":4,"doc_module_name":46,"category_name":136,"show_sort_weight":106,"slug":137},19,"General","general"]