惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Apple Machine Learning Research
Apple Machine Learning Research
博客园 - 三生石上(FineUI控件)
雷峰网
雷峰网
WordPress大学
WordPress大学
S
SegmentFault 最新的问题
博客园 - 叶小钗
The Cloudflare Blog
T
Tailwind CSS Blog
Hugging Face - Blog
Hugging Face - Blog
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
月光博客
月光博客
小众软件
小众软件
罗磊的独立博客
酷 壳 – CoolShell
酷 壳 – CoolShell
大猫的无限游戏
大猫的无限游戏
阮一峰的网络日志
阮一峰的网络日志
V
V2EX
美团技术团队
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
博客园 - 聂微东
量子位
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
宝玉的分享
宝玉的分享

Hacker News - Newest: "AI"

AI can't read an investor deck AI as an attorney? Student uses ChatGPT, Gemini to sue UW over alleged racial discrimination Hacking MCP Servers in AI Systems – The Rug Pull: Tool Changes After Approval GitHub - MeepCastana/KubeezCut: Free Web based video editor Can AI judge journalism? A Thiel-backed startup says yes, even if it risks chilling whistleblowers Coming soon: 10 Things That Matter in AI Right Now DARPA built an AI to fact-check enemy weapons claims What explains heterogeneity in AI adoption? When AI Meets Muscle: Context-Aware Electrical Stimulation Promises a New Way to Guide Human Movements - Department of Computer Science AI Changed How We Build. It Did Not Change What Matters. Linux rules on using AI-generated code - Copilot is OK, but humans must take 'full responsibility for the… Meta spins up AI version of Mark Zuckerberg to engage with employees Code Mode: Let Your AI Write Programs, Not Just Call Tools | TanStack Blog GitHub - Delavalom/graft: Go framework for building AI agents. Type-safe tools, multi-provider (OpenAI, Anthropic, Gemini, Bedrock), zero vendor SDKs. India's TCS tops estimates, says new AI models did not dent services demand Gen Z's fading AI hype Strong feeling: we are in a folded AI reality GitHub - machinarii/total-recall-catalog: A reference catalog of latest knowledge retrieval, memory & RAG systems GitHub - mensfeld/code-on-incus: Give each AI agent its own isolated machine with root, Docker, and systemd. Active defense detects and stops threats automatically.. Quantization, LoRA, and the 8% Problem: Benchmarking Local LLMs for Production AI Iran war: We spoke to the man making Lego-style AI videos that experts say are powerful propaganda Powell, Bessent discussed Anthropic's Mythos AI cyber threat with major U.S. banks GitHub - immartian/bellamem: Persistent belief-graph memory for AI agents. Retrieves decisive context by importance — not recency, not RAG, not /compact. recursive-mode: The Repo-Native Operating System for AI Engineering After the attack on Sam Altman's home, will AI CEO's go on the offensive? The biggest advance in AI since the LLM Opus 4.6 vs GPT 5.4 One Prompt Unity World Generation Test “AI polls” are fake polls Client Challenge Can AI be a 'child of God'? Inside Anthropic's meeting with Christian leaders
AI chatbots know more about you than you realise
sebg · 2026-04-23 · via Hacker News - Newest: "AI"

From a few basic questions, the kind of day-to-day things you might ask a friend or family member, an AI chatbot can learn more about you than those who have known you for years. Emotional maturity, relationship status, financial constraints, professional ambition and even your health — none of which you were asked about directly, and most of which you hadn’t realised you’d shared.

Using the powerful pattern processing inherent to artificial intelligence, chatbots simply inferred these details.

For years, the ability to build such a rich profile of you required something only a handful of companies had: the infrastructure to collect and process your online behaviour on a massive scale. That’s no longer true. Now, that same understanding can emerge from a single exchange — and the privacy consequences are profound.

ai_privacy

Google tracks your clicks; AI interprets your words

Traditional tech monoliths, like Meta, Amazon, Google and Apple, collect your data on a scale that’s nearly impossible to comprehend. Every click, every search, every location, every purchase.

Here’s a simplified explanation of how those big companies gather your data.

This graphic shows how companies generally collect your data. First, you sign up for their services. Then, when setting up your accounts, you share some data about yourself, such as your name, age, e-mail address and gender. You also agree to the privacy policies. As you use the services, the companies collect loads of data about you. That means everything you watch, post, click, track, share, comment on, upload and buy. The companies store the data and use it to personalise your service. (That usually means ads).

These companies have more than enough data to make a detailed profile of you.

Take Amazon: It knows the name, price and purchase date of every Australian guidebook Marcus bought. It knows the exact time he spent looking for a new carry-on suitcase. It knows that his mouse hovered on an advertisement for a Visiting Down Under audiobook and that the next website he visited was a Melbourne-based accommodation provider.

From those data points – and millions more – Amazon likely knows Marcus is visiting Melbourne, Australia.

But Claude, an AI chatbot built by Anthropic, figured out most of the same information when Marcus asked it a single question:

I almost caused an accident — what is a hook turn?!

+

Unlike traditional platforms, an AI chatbot doesn’t need piles of individual data points to understand you. It picks up meaning from the language itself. Not just what you say, but also how you say it. Through your word choices, sentence structure, cultural references and details mentioned in passing, you’re unknowingly revealing a lot about yourself.

And what it can infer is pretty astounding.

From just a few questions, an AI chatbot was able to build a detailed profile of Marcus – with no follow-up, no back-and-forth, just the wording.

Profiling

I have a protein shake every morning but I'm hungry by 10am. What else should I eat for breakfast?

My boss keeps changing priorities and I never know what to expect. How do I bring it up without saying the wrong thing?

Best way to build grip strength for deadlifts?

Is it still worth submitting Pokemon cards to PSA or is the grading backlog too bad now?

My ah ma's braised pork belly is so much better than mine. Why can't I ever get it right?

I almost caused an accident — what is a hook turn?!

Is Uniqlo in Australia cheaper?

What's a good anniversary gift for my girlfriend? She's really into skincare.

marcus

Looking for glasses. Something similar but more affordable. Any recommendations?

What are some bouldering gyms near one-north?

Best credit card for collecting miles?

ai_privacy

With just minimal input, AI can produce surprisingly in-depth output

Marcus isn’t a real person. We invented him: his age, his interest in Pokemon, his relationships, his anxiety. We imagined the questions someone like him might ask a chatbot and gave those questions – nothing else – to Claude, ChatGPT and Gemini. All three chatbots made similar inferences, though there were slight differences between them. Their assessments were detailed, and they correctly identified many of the attributes we gave Marcus, such as his sex, age, location, job, nationality, ethnicity, emotional state and hobbies.

Marcus was based on the work of researchers at Swiss university ETH Zurich who did something similar, but on a much larger scale. In 2024, they found that AI models can infer personal attributes, including location, income, sex, age, occupation and relationship status from conversational text with up to 85 per cent accuracy. Since then, these models have only improved.

“Inferences can happen from things where humans, on a first read, don’t think there’s much information,” explained Dr Robin Staab, one of the postdoctoral researchers on the project. “But actually, there is a lot of information about me in the way that I write things.”

Research confirming these capabilities extends well beyond the work of Dr Staab and his colleagues. A study from Columbia Business School found that ChatGPT could build a complete personality profile of someone just from their Facebook posts — no self-description required. Another found that an AI chatbot, given a short description of a person, could answer questions about them as accurately as a close friend would. And a study published just last month found that AI can figure out how you vote from your online posts, even when nothing you’ve written is explicitly political.

AI chatbots can infer these details because the language we use is full of signals. Our word choices leak information about us constantly.

Consider this question:

Is it okay to wear a bunnyhug at my age?

Nearly every word reveals something about the writer.

Is it okay to wear a bunnyhug at my age?

+

Is it okay to wear a bunnyhug at my age?

+

Is it okay to wear a bunnyhug at my age?

+

During training, AI processes an enormous cross-section of human writing and learns, statistically, which word choices cluster with which backgrounds, demographics, emotional states and personality traits. For example, an AI chatbot can infer that the writer of this question is likely from Saskatchewan because the model encountered that term almost exclusively in Saskatchewan-specific contexts.

Put it all together, and the AI chatbot can deduce an uncomfortable amount about a person just from their text.

Those who work in the security industry have been surprised.

“We are having what seem to be innocent conversations with the chatbot, but we are actually revealing a lot. We are revealing a lot more than we think we are,” said Dr Luis Costa, research lead at Surfshark, a digital privacy company. His team did a small study with popular AI chatbots, finding that they can accurately summarise nearly everything users share in conversation and can even infer additional personal details.

Even as someone working in cybersecurity, who is very aware and conscious of these things because of my line of work, it was still quite surprising for me to find out how much the chatbots can infer about me.

Dr Luis Costa, research lead at Surfshark

Certainly, this ability to infer rich detail from our words could be beneficial. Artificial intelligence can screen for depression and anxiety and flag early signs of a mental health crisis. They can even detect indications of Alzheimer’s and correctly identify Type 2 diabetes from voice recordings alone. And, of course, it’s practical for AI chatbots to know information about you. It makes the product more useful.

But despite the potential benefits, this capability gets unsettling fast. If a chatbot can build a profile from a casual question you typed on purpose, imagine what it could do with a decade of forum posts, reviews and Reddit comments you assumed no one could trace back to you.

ai_privacy

AI could mean the death of anonymity

For Dr Staab, Dr Costa and other AI researchers, the implications for individual privacy are extremely concerning. Anyone can feed anonymous text – Glassdoor reviews, old blog posts, support group chats – into an AI and use it to piece together who wrote it. A person who thought they were anonymous isn’t any more.

This graphic shows how someone could figure out the writer of an anonymous post. First, someone finds text that Marcus anonymously posted online. They put the text in an AI chatbot. It infers details about the writer of the text and tries to find a match by searching the internet and cross-referencing sources. Ultimately, this simple process may be enough to identify Marcus as the writer.

This deanonymisation is easier than you think. In the US, for example, researchers realised decades ago that nearly 90 per cent of Americans could be uniquely identified by just their zip code, birth date and gender. Until recently, identifying someone through a few data points was difficult and often impractical; AI makes it significantly easier to find those details and make a potential match.

“This is a thing we’re calling democratised surveillance,” said Dr Tianshi Li, an assistant professor at Northeastern University.

It’s no longer just large tech companies, with proprietary customer data, that can create rich profiles. By connecting the dots between harmless bits of information, AI chatbots can craft detailed profiles from anonymous text.

“Previously, we were just thinking ‘do I trust Google’ or ‘do I trust Amazon’ to have my data. And maybe people are just getting used to that,” Dr Li said. “But now, anybody can search and know more about you just from all the digital traces that you have left on the public internet. This is another level of threat that we haven’t seen before.”

ai_privacy

Deanonymisation is fast, cheap and easy

Dr Li should know about this potential for deanonymisation better than anyone. She did it herself.

In December 2025, Anthropic publicly released the text of 1,250 anonymised interviews that it conducted with professionals about their views on AI — 125 of them scientists. Within a day, Dr Li had worked out the identity of a number of those scientists. Using a publicly available AI tool, she was able to deanonymise 25 per cent of the interviews that mentioned specific scientific papers.

“I wanted to show that it is feasible to use the current, off-the-shelf AI chatbots to conduct this kind of reidentification attack,” she said.

This means third parties – whether a corporation, a government, or just a stranger on the internet – can now do what once required a team of trained investigators. And do it in minutes, with almost no money.

The stuff that I just put out there on the internet, I post it on an online forum, I post it on Twitter, I post it on Reddit. This can be scraped and then analysed. Not necessarily by these (AI) companies. It can be analysed by anyone with access to (AI).

Dr Mark Vero, Dr Staab’s co-author at ETH Zurich.

A separate research team at ETH Zurich, in collaboration with Anthropic, demonstrated that AI could correctly identify about two-thirds of anonymous Hacker News users by cross-referencing their posts against LinkedIn profiles. They warned that the same techniques could let governments track journalists or dissidents, corporations tie anonymous forum posts to customer profiles and attackers build detailed personal profiles to make social engineering scams more convincing.

The authors write: “Users, platforms and policymakers must recognise that the privacy assumptions underlying much of today’s internet no longer hold.”

ai_privacy

For some AI privacy concerns, there’s no simple opt-out

The ability to make such accurate inferences is far from the only privacy concern posed by AI. Researchers who analysed 321 real-world AI incidents found that in 93 per cent of cases, AI either created a new type of privacy risk or made an existing one significantly worse.

There are ways to combat some of those risks. Don’t give sensitive information to chatbots – no NRIC numbers, no credit card bills, no personal photos. Be wary of the fun features that chatbots keep adding: Dr Li calls image uploaders, voice tools, memory features and customisations “data collection honeypots”. They all generate detailed behavioural profiles.

It’s easy enough not to share materials like financial documents and medical files. But what happens when we don’t even know we’re sharing sensitive information? One of Marcus’ most innocuous questions, “I almost caused an accident – what is a hook turn?!”, revealed his exact location. That’s something even a privacy-conscious user would miss.

“One should rethink their interactions on the internet,” said Dr Vero. “One should not assume that just by typing under a pseudonym, they will not be identified.”

The problems of inference and deanonymisation have been understudied, according to research by Dr Li. Over the last decade, only 6 per cent of studies on AI privacy were about inference.

Maybe at some point, there is just no guarantee of anonymity for a person posting anything online. I’m not saying that we’re already there at this moment. And so I think that’s why it’s really important to do more research in this area.

Dr Tianshi Li, assistant professor at Northeastern University