LLM agents design new privacy attacks — in natural language.
Final AUC: 0.73 (+0.19 vs. human baseline)