PerceptFence controls sensitive content in screen-share AI assistants
PerceptFence: Content-Mediation Architecture and Deterministic Coverage for Screen-Share AI Assistants
Cryptography and Security
Summary
When people share their screens with AI helpers, private information can unintentionally be seen or kept by the AI. The researchers created PerceptFence, a system that carefully filters what the AI can see and remember from the screen to protect privacy better. They tested it using tricky fake data and found it was better at hiding secrets than other tools they compared it to. This system is not meant for live use yet but shows a clear way to limit what private content an AI assistant can access.
What this means in practice
- •For enterprise software developers: Implement controlled data filters in screen-sharing AI tools to better protect user privacy during live sessions.
- •For security teams in tech companies: Improve risk assessments of AI assistants by testing them with simulated secrets to ensure personal data leakage is minimized.
Authors
Asmita Negi, Neeraj Kumar Singh Beshane
Abstract
Live screen-share AI assistants observe raw screen and speech streams, but users have little runtime control over what an assistant may observe, retain, or disclose. Prompt-level privacy settings are insufficient because sensitive content enters through the capture stream. We present PerceptFence, a content-layer mediation architecture between capture, memory, and model responses, with a deterministic synthetic-fixture scaffold; the artifact omits live capture, category inference, authenticated re-consent, cross-session state, and an external model adapter. On 9,600 protocol-documented adversarial strings scored by a separately implemented exposure oracle, PerceptFence neutralises 0.828 of digit-PII payloads on the 5 seeds both systems run, versus 0.183 for Microsoft Presidio; outside that family Presidio leads 0.238 to 0.154, so the overall 0.398 to 0.260 comparison is only indicative. We then evaluate the path a deployed assistant uses: 480 synthetic developer-support screens rendered by Chrome, degraded, and read by OCR, with rules frozen before testing and three screen types held out. PerceptFence neutralises 889 of 968 OCR-surviving secrets and PII values (0.918; Wilson 95% 0.899-0.934) against 0.581 for Presidio and 0.179 for gitleaks, and 0.974 on the held-out screen types, at a measured cost of 0.763 task-token retention on those types. The contribution is a documented mediation architecture and an evaluation method with explicit coverage boundaries, not a claim of live deployment, formal privacy, novel redaction primitives, or general model robustness.