PrivWeb: Unobtrusive and Content-aware Privacy Protection For Web Agents
Authors
Paper Title
PrivWeb: Unobtrusive and Content-aware Privacy Protection For Web Agents
Publication Info
- Topic area: Privacy protection mechanisms for GUI-based web agents.
- Keywords: Privacy, web agents, GUI agents, LLMs, user control, data redaction, situational awareness, tiered delegation, cognitive load, privacy notifications.
Background and Problem
- Problem / challenge: Web agents that automate GUI interactions often require extensive access to interface content, leading to significant privacy risks. Current privacy mechanisms lack transparency, granularity, and user control, leaving users uncertain and distrustful of agents' data practices.
- Significance: Addressing these privacy risks is critical to fostering trust in web agents, enabling their safe and effective use in tasks involving sensitive data, such as financial transactions, personal communications, and online shopping.
- Motivation and related work: Prior work has explored privacy risks in GUI agents, including flawed reasoning, adversarial attacks, and interface-induced data leaks. Existing notification and control mechanisms, such as cookie consents and runtime permission prompts, are insufficient for the dynamic and autonomous nature of web agents. This paper builds on these findings to address the gap in user-centric privacy protection for web agents.
Solution
- Proposed approach: PrivWeb, a localized add-on for web agents, provides unobtrusive, content-aware privacy protection by redacting sensitive data and enabling tiered user control based on data sensitivity.
- Novelty:
- A tiered delegation model that balances automation with user control by pausing execution for high-sensitivity data and providing ambient notifications for low-sensitivity data.
- A localized LLM-based system for real-time detection and redaction of sensitive information directly on the user’s device.
- An interface design that enhances situational awareness through in-situ highlighting and a privacy panel for granular control.
- Empirical evidence demonstrating improved user trust and privacy protection without increasing cognitive load.
- Procedure and key techniques:
- Sensitive data is detected using a localized LLM (Qwen3-8b) by parsing DOM elements.
- Detected data is classified into high, medium, and low sensitivity categories.
- High-sensitivity data triggers execution pauses with mandatory user confirmation, while low-sensitivity data is redacted by default with optional user intervention.
- A privacy panel and in-situ highlights provide real-time feedback and control options.
- Technical evaluations and user studies validate the system’s accuracy, latency, and usability.
Results
- Concrete findings:
- PrivWeb achieved an average recall of 93.3% in detecting sensitive data, with 100% recall for critical categories like financial, health, and geo-location data.
- User intervention was required in only 8.5% of cases, with a 96.7% recovery rate for agent errors caused by redaction.
- False negatives were limited to 3.7%, with minimal privacy leakage (0.4% inference rate for redacted data).
- Advantage over baselines:
- PrivWeb significantly improved perceived privacy protection, trust, and reduced frustration compared to transparency-only (n/c) and no-control (n/b) baselines.
- Maintained comparable task completion rates (71.4%) to baselines, despite rigorous privacy filtering.
- Experiments / evaluation:
- A technical evaluation using a custom dataset of 107 sessions and 2,189 sensitive data instances demonstrated high detection accuracy and manageable latency (6.42 seconds per DOM page for Qwen3-8b).
- A user study (N=14) assessed cognitive load, trust, perceived control, and privacy protection across three conditions (PrivWeb, n/c, n/b), showing significant user preference for PrivWeb.
- Limitations and future work:
- Limited to text-based DOM elements; does not address image-based or non-textual GUI elements.
- Short-term user study; long-term effects like habituation and trust evolution remain unexplored.
- Dataset and evaluation focused on specific models and tasks; broader generalization and open-sourcing of datasets are needed.
Summary
PrivWeb is a privacy protection add-on for web agents that uses a localized LLM to detect and redact sensitive data while providing tiered user control. It enhances trust and privacy protection through in-situ notifications and execution pauses for high-sensitivity data. Technical evaluations and user studies confirm its effectiveness in balancing automation and user oversight without increasing cognitive load. Future work should explore long-term user behavior, extend protection to non-textual elements, and generalize findings across diverse contexts.
Research Questions / Practical Problems
Question signals indexed for this paper.
- 75%
PrivacyAkinator: Articulating Key Privacy Design Decisions by Answering LLM-Generated Multiple-choice Questions
CHI '26· Explainable AI (XAI) +3
- 71%
Understanding Challenges for Developers to Create Accurate Privacy Nutrition Labels
CHI '22· Privacy by Design & User Control +1
- 71%
The Privacy Paradox of LLMs: User Perceptions and the Reality of PII Leakage
CHI '26· Explainable AI (XAI) +2
- 71%
“Don’t Look, But I Know You Do”: Norms and Observer Effects in Shared LLM Accounts
CHI '26· Human-LLM Collaboration +2
- 67%
Contextualizing Privacy Decisions for Better Prediction (and Protection)
CHI '18· Privacy by Design & User Control +1
- 67%
Privacy Champions in Software Teams: Understanding Their Motivations, Strategies, and Challenges
CHI '21· Privacy by Design & User Control +1
- 63%
Bridging the Gap Between Usable Security Research and Open-Source Practice — Lessons From a Long-Term Engagement With VeraCrypt
CHI '25· Privacy by Design & User Control +2
- 63%
Development, Evaluation, and Implementation of SEQR -- a Usable Secure QR Code Scanner
CHI '26· Privacy by Design & User Control +2
- 63%
Privacy Control in Conversational LLM Platforms: A Walkthrough Study
CHI '26· Explainable AI (XAI) +3
- 63%
Relational Gains, Privacy Strains: Exploring Users’ Perceptions and Experiences with ChatGPT’s Memory Feature
CHI '26· Human-LLM Collaboration +3
Based on Jaccard similarity of research subtopics & professions (≥60%)