<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/mosaicleaks-can-your-research-agent-keep-a-secret--zuzoxsbo2" -->

---
title: MosaicLeaks: Can your research agent keep a secret?
description: MosaicLeaks is a new benchmark exposing a privacy risk in deep research agents: when agents interleave private local documents with public web searches, their...
canonical: https://daily.dev/posts/mosaicleaks-can-your-research-agent-keep-a-secret--zuzoxsbo2
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: MosaicLeaks: Can your research agent keep a secret? | daily.dev
og:description: MosaicLeaks is a new benchmark exposing a privacy risk in deep research agents: when agents interleave private local documents with public web searches, their...
og:url: https://daily.dev/posts/mosaicleaks-can-your-research-agent-keep-a-secret--zuzoxsbo2
og:image: https://api.daily.dev/og/posts/zUZOXsBo2.png
og:image:alt: MosaicLeaks: Can your research agent keep a secret?
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# MosaicLeaks: Can your research agent keep a secret?

**[Hugging Face](https://daily.dev/sources/huggingface)** · 10 min read · 2 upvotes · 0 comments

## Summary

MosaicLeaks is a new benchmark exposing a privacy risk in deep research agents: when agents interleave private local documents with public web searches, their query logs can leak sensitive enterprise information through the 'mosaic effect' — where individually benign queries collectively reveal private facts. Testing shows that simply prompting agents to avoid leakage barely helps, and training purely for task performance actually worsens leakage (from 34% to 51.7%). The proposed solution, Privacy-Aware Deep Research (PA-DR), uses a dual reward system combining situational task rewards with a learned privacy classifier. PA-DR raises strict chain success from 48.7% to 58.7% while cutting answer/full-information leakage from 34% to 9.9%, and achieves this with 5-6x better sample efficiency than outcome-only RL.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://huggingface.co/blog/ServiceNow/mosaicleaks>

## Questions this post answers

### What is the mosaic effect in AI research agents and why does it cause privacy leaks?

The mosaic effect occurs when a research agent's individual web search queries look benign on their own but, when combined, let an observer reconstruct private information. For example, queries referencing a cloud-migration milestone, a date, and a vendor name can together reveal that a company migrated 70% of its infrastructure to the cloud by a specific month, even though no single query stated that fact directly.

_Teams building agentic research tools can track emerging privacy-preserving RL techniques like this one on daily.dev._

### Does training a research agent only for task performance make it leak more private information?

Yes, training an agent purely to solve more research chains correctly increased leakage substantially in tests on Qwen3-4B, with strict chain success rising from 48.7% to 59.3% while answer or full-information leakage climbed from 34.0% to 51.7%. The model learned to pack more context into web queries, which improved retrieval but exposed more private fragments to an observer.

_Engineers weighing RL reward design tradeoffs for agents can follow research like this via daily.dev._

### Does telling an AI agent not to leak private information in its prompt actually prevent leakage?

No, adding a prompt instruction telling an agent not to issue web queries that leak local information only helped slightly and inconsistently. For Qwen3-4B, it lowered answer or full-information leakage from 34.0% to 25.5%, but strict chain success dropped from 48.7% to 44.5%, mainly because the agent simply issued fewer web queries rather than constructing safer ones.

_Developers deciding between prompting and training for agent safety can track this kind of evidence on daily.dev._

## Similar posts on daily.dev

- [Privacy risks of agentic oversharing on the Web](https://daily.dev/posts/privacy-risks-of-agentic-oversharing-on-the-web-pfn6uzis0) · Brave · 2 upvotes · 0 comments
- [Frontier AI models haemorrhage sensitive data](https://daily.dev/posts/frontier-ai-models-haemorrhage-sensitive-data-aky1ifa1f) · LeadDev · 0 upvotes · 0 comments
- [Schneier on Security](https://daily.dev/posts/schneier-on-security-aryryygjo) · Schneier on Security · 1 upvotes · 1 comments
- [ShadowLeak Vulnerability in ChatGPT Deep Research](https://daily.dev/posts/shadowleak-vulnerability-in-chatgpt-deep-research-ubajwcvcz) · AI Cyber Insights · 0 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security), [#llm](https://daily.dev/tags/llm), [#ai-agents](https://daily.dev/tags/ai-agents), [#privacy](https://daily.dev/tags/privacy), [#reinforcement-learning](https://daily.dev/tags/reinforcement-learning)

[View this post on daily.dev](https://daily.dev/posts/mosaicleaks-can-your-research-agent-keep-a-secret--zuzoxsbo2)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"MosaicLeaks: Can your research agent keep a secret?","url":"https://daily.dev/posts/mosaicleaks-can-your-research-agent-keep-a-secret--zuzoxsbo2","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/mosaicleaks-can-your-research-agent-keep-a-secret--zuzoxsbo2"},"datePublished":"2026-06-18T18:13:15.193Z","dateModified":"2026-09-13T18:36:24.844Z","description":"MosaicLeaks is a new benchmark exposing a privacy risk in deep research agents: when agents interleave private local documents with public web searches, their...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/e2f8f8e492230ff40e992ee072b389f4?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/e2f8f8e492230ff40e992ee072b389f4?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"Hugging Face","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"Hugging Face","logo":"https://media.daily.dev/image/upload/t_logo,f_auto/v1/logos/f1f55c67d81a4330acf5b90b26b0c8e1","url":"https://daily.dev/sources/huggingface"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/mosaicleaks-can-your-research-agent-keep-a-secret--zuzoxsbo2","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":2},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"security,llm,ai-agents,privacy,reinforcement-learning","timeRequired":"PT10M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Hugging Face","item":"https://daily.dev/sources/huggingface"},{"@type":"ListItem","position":3,"name":"MosaicLeaks: Can your research agent keep a secret?"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/mosaicleaks-can-your-research-agent-keep-a-secret--zuzoxsbo2#faq","mainEntity":[{"@type":"Question","name":"What is the mosaic effect in AI research agents and why does it cause privacy leaks?","acceptedAnswer":{"@type":"Answer","text":"The mosaic effect occurs when a research agent's individual web search queries look benign on their own but, when combined, let an observer reconstruct private information. For example, queries referencing a cloud-migration milestone, a date, and a vendor name can together reveal that a company migrated 70% of its infrastructure to the cloud by a specific month, even though no single query stated that fact directly. Teams building agentic research tools can track emerging privacy-preserving RL techniques like this one on daily.dev."}},{"@type":"Question","name":"Does training a research agent only for task performance make it leak more private information?","acceptedAnswer":{"@type":"Answer","text":"Yes, training an agent purely to solve more research chains correctly increased leakage substantially in tests on Qwen3-4B, with strict chain success rising from 48.7% to 59.3% while answer or full-information leakage climbed from 34.0% to 51.7%. The model learned to pack more context into web queries, which improved retrieval but exposed more private fragments to an observer. Engineers weighing RL reward design tradeoffs for agents can follow research like this via daily.dev."}},{"@type":"Question","name":"Does telling an AI agent not to leak private information in its prompt actually prevent leakage?","acceptedAnswer":{"@type":"Answer","text":"No, adding a prompt instruction telling an agent not to issue web queries that leak local information only helped slightly and inconsistently. For Qwen3-4B, it lowered answer or full-information leakage from 34.0% to 25.5%, but strict chain success dropped from 48.7% to 44.5%, mainly because the agent simply issued fewer web queries rather than constructing safer ones. Developers deciding between prompting and training for agent safety can track this kind of evidence on daily.dev."}}]}
```

