PerceptFence: Content-Mediation Architecture and Deterministic Coverage for Screen-Share AI Assistants
PerceptFence mediates screen-share AI assistant capture to redact secrets, beating Presidio on OCR-surviving PII in synthetic tests.
PerceptFence is a content-layer mediation architecture between screen and speech capture, memory, and model responses for live screen-share AI assistants. The artifact is a deterministic synthetic-fixture scaffold and omits live capture, category inference, authenticated re-consent, cross-session state, and an external model adapter. On 9,600 adversarial strings it neutralized 0.828 of digit-PII payloads versus 0.183 for Microsoft Presidio on shared seeds, while Presidio led outside that family. On 480 synthetic Chrome screens it neutralized 889 of 968 OCR-surviving secrets and PII values (0.918), versus 0.581 for Presidio and 0.179 for gitleaks, with 0.763 task-token retention on held-out types.
- Mediation sits between capture, memory, and model responses.
- Artifact omits live capture and an external model adapter.
- It neutralized 889 of 968 OCR-surviving secrets and PII values.
- Digit-PII beats Presidio; Presidio leads outside that family.
- Held-out screens scored 0.974 with 0.763 token retention.
Full article222 words · extracted from arxiv.org · click to collapse
Live screen-share AI assistants observe raw screen and speech streams, but users have little runtime control over what an assistant may observe, retain, or disclose. Prompt-level privacy settings are insufficient because sensitive content enters through the capture stream. We present PerceptFence, a content-layer mediation architecture between capture, memory, and model responses, with a deterministic synthetic-fixture scaffold; the artifact omits live capture, category inference, authenticated re-consent, cross-session state, and an external model adapter. On 9,600 protocol-documented adversarial strings scored by a separately implemented exposure oracle, PerceptFence neutralises 0.828 of digit-PII payloads on the 5 seeds both systems run, versus 0.183 for Microsoft Presidio; outside that family Presidio leads 0.238 to 0.154, so the overall 0.398 to 0.260 comparison is only indicative. We then evaluate the path a deployed assistant uses: 480 synthetic developer-support screens rendered by Chrome, degraded, and read by OCR, with rules frozen before testing and three screen types held out. PerceptFence neutralises 889 of 968 OCR-surviving secrets and PII values (0.918; Wilson 95% 0.899-0.934) against 0.581 for Presidio and 0.179 for gitleaks, and 0.974 on the held-out screen types, at a measured cost of 0.763 task-token retention on those types. The contribution is a documented mediation architecture and an evaluation method with explicit coverage boundaries, not a claim of live deployment, formal privacy, novel redaction primitives, or general model robustness.
Text extracted automatically; images, tables and formatting may be missing. Original: https://arxiv.org/abs/2609.34027