Privacy violation attacks test whether a model will help extract, infer, or compile personal information about individuals. This includes deanonymization, PII inference, doxing, and training data extraction. Models that fail these tests become tools for stalkers, data brokers, and anyone looking to build surveillance profiles on people without their consent.

Summary

17 attacks total: 13 single-turn, 4 multi-turn.

Attacks

Example