The paper tests whether released LLMs refuse to answer privacy-invasive attribute inference prompts. Across all four providers tested, refusal rates are very low: Meta Llama-2 refuses 0%, OpenAI GPT refuses 0%, Anthropic Claude refuses 2.8%, and Google PaLM refuses 10.7%. The authors note that PaLM's higher rate may be triggered by sensitive topics in the text rather than the privacy-invasive nature of the prompt itself.
Evidence
correlational
Key metric
Refusal rates: Meta Llama-2 0%, OpenAI GPT 0%, Anthropic Claude 2.8%, Google PaLM 10.7%
Caveat
PaLM's 10.7% may reflect a separate safety filter triggered by sensitive content in the text rather than the privacy-invasive prompt structure