Sensitive information is defined by the specific domain and the intended use, not by a universal category. Conventional redaction systems—such as privacy filters and named‑entity recognizers—fix a taxonomy during training, which forces a full retraining whenever a new domain appears. To break this limitation we introduce ASIRF (Agentic Sensitive Information Redaction Framework), which retrieves domain‑specific definitions from a flexible knowledge base at inference time, eliminating the need for model fine‑tuning.
ASIRF offers two architectural variants:
- Three‑call multi‑agent pipeline – three separate agents handle (1) domain detection, (2) definition retrieval, and (3) information redaction.
- Single‑agent variant – the same agent performs the three steps sequentially, reducing call overhead.
We evaluate both variants on ten small open‑weight models across eight datasets, including out‑of‑distribution fictional domains, and compare against the OpenAI Privacy Filter (OPF) as a trained‑classifier baseline. In 80 model‑domain combinations, ASIRF achieves higher recall than OPF in 68 cases (85%), with at least one of the two architectures outperforming OPF. The few shortfalls are confined to domains that belong to OPF’s training distribution, highlighting ASIRF’s superior adaptability to unseen domains.
Crucially, ASIRF requires only a few dozen expert‑authored definitions per domain and no labeled training data, yet delivers strong redaction performance. This demonstrates the promise of knowledge‑base‑driven agents for sensitive‑information handling and offers a practical path toward cross‑domain privacy protection.
Review: ASIRF externalizes domain knowledge, enabling rapid, training‑free adaptation to new contexts and markedly improving the practicality and flexibility of cross‑domain privacy filtering.