$3 Buys All Your Secrets? The Privacy Iceberg Crisis in the LLM Agent Era
Imagine walking down a busy street. You feel safe as long as you're not wearing your ID card around your neck or shouting your safe-deposit password in public.
In the past, that was mostly true. If someone wanted to figure out who you are, where you live, what you like, or what you complained about online last year, they had to hire a professional private investigator, spend weeks digging through records, and pay a hefty fee. That "expensive price tag" was itself a natural umbrella protecting ordinary people's privacy.
But now, that umbrella is broken.
In May 2026, a group of researchers at Zhejiang University published a chilling arXiv paper ("Profiling for Pennies: Unveiling the Privacy Iceberg of LLM Agents").
The paper exposes a harsh reality: today's AI agents, for less than $3 and in just 10 minutes, can piece together a detailed profile of a complete stranger with up to 90% accuracy.
What Is the "Privacy Iceberg"?
Co-author Jiahao Chen offers a vivid metaphor: the Privacy Iceberg.
Before AI, privacy leaks mostly revealed just the "tip of the iceberg":
1. Explicitly Searched: Data you enter directly online—your name, phone number. If you don't provide it, others can rarely find it. 2. Contextually Inferred: The part lurking below the surface. For example, you post a photo of a sunset; AI combines the posting time, weather forecast, and a recognizable office building in the frame to pinpoint your residential compound and building. 3. Deeply Aggregated: The deepest layer. AI stitches together a complaint you posted on a forum ten years ago, a movie ticket you shared on social media five years ago, and a "like" you clicked last week. From these it can infer your career trajectory, spending level, even political leanings and emotional state.
Why Is AI Profiling So Cheap?
Here's how the profiling tool, IcebergExplorer, works:
Traditional search is "keyword matching"—you search a name and get a list of people with that name.
An AI agent is a "reasoning engine." Given a single clue (say, an obscure username), it sniffs across the web:
- On Twitter, it finds the username is linked to an email address.
- With that email, it finds your GitHub account and code from five years ago containing your real name.
- With the real name, it locates your employer on LinkedIn.
- Then it finds your office phone number on the company website, and even picks you out of a colleague's team-building group photo.
- Model providers: Add "deep privacy filters" to AI; cross-platform, cross-time deep reasoning should trigger warnings.
- Data publishers: Reduce data "linkability"—don't leave the same digital fingerprint everywhere.
- Individuals: Realize that every image you post and every sentence you write is not isolated. They are pixels assembling a giant high-definition portrait called "you."
The entire process is fully automated, with no human intervention. Because LLMs reason so well, seemingly unrelated "digital fragments" all become pieces of a map leading to your doorstep.
What Does This Mean for Us?
When the cost of "doxxing" drops from tens of thousands of dollars to $3, and the workload shrinks from months to 10 minutes, the boundary of privacy has effectively disappeared. Anyone with ill intent can, for the price of a cup of coffee, buy up every trace you've left in the digital world over the past twenty years.
What Can We Do?
The paper's authors not only sound the alarm but also offer recommendations:
Protect the bottom of your iceberg—don't let it become someone else's cheap prey.