S0108RS3-T06-S0108-Z · Full risk code

Attribute Inference Revealing Undisclosed Traits

屬性推斷揭露未公開特徵

Operation & Monitoring
Risk Description

When a third party analyzes the output patterns of a recommendation system to infer sensitive states users never disclosed, then uses them for commercial targeting; due to unmitigated control gaps, when users become aware, they question the organization's data practices, and the organization struggles to explain how the inferences were produced, triggering compliance exposure and operational reputational costs.

Framework Mappings

OWASP Top 10 for LLMLLM02
NIST AI 600-1Data Privacy
MITRE ATLASAML.T0024
ISO/IEC 5338運作與監控
MIT AI Risk RepositoryDomain 2

Risk Treatment & Implementation Guidance

Test for sensitive-attribute inference before launch, examining whether output patterns can reveal undisclosed characteristics; Limit output granularity and observable dimensions to hinder third-party pattern analysis; Define handling rules for inferred attributes in the data-use policy, prohibiting undisclosed commercial targeting