When and Which LLMs Ask for More: Benchmarking Sensitive-Data Solicitation
Xinlei XU ⋅ Baoer Ye
Abstract
Privacy evaluations often don't start until a person's private information is shared. We study an earlier, model-controlled choice: whether an assistant asks the user to provide more. We define \emph{personal solicitation} as a closing question or request about the user's situation, feelings, history, relationships, health, or circumstances. Across six pinned API endpoints, each tested on 300 emotional and 300 length-matched task openers, solicitation appears in 58.3\% (1049/1800) versus 3.3\% (59/1800) of replies; paired human supporters solicit in 65.0\% (195/300). With two fixed user continuations, solicitation changed from 58.3\% (1049/1800) to 49.6\% (893/1800) to 33.6\% (604/1800). A one-line instruction changes solicitation (Claude: $-$68.3 points; GLM: $-$34.7 points), while paired LLM-judge helpfulness on a 1--5 scale changes by Claude: +0.58 and GLM: +0.14. Surprisingly, it removes a direct safety question in one of two prespecified risk pairs, so it is not recommended as written. Even though our experiments simulate opportunistic solicitation, which invites but does not guarantee user disclosure, it nevertheless underscores a potential downstream risk of increased collection of sensitive data that ought to be studied.
Chat is not available.
Successful Page Load