Lineage-gated agent memory wipes 18.8-25.5% cross-department leakage at 13.8μs overhead
Venkata M Sangaraju · hf · 2026-10-09
This paper introduces the Analytical Memory Unit (AMU), tackling two risks in enterprise agents sharing a memory store: sensitive data leaking through legitimately computed results, and departments silently computing the same-named KPI with conflicting logic. Existing systems (MemGPT, Zep, A-MEM) gate retrieval by content/ownership/role but not derivation.
The approach attaches a full derivation lineage graph to every cached result, serving a hit only when the requester is authorized for every column touched, at O(n) worst case.
Key results:
- Removes 18.8-25.5% cross-department leakage of naive content-gated memory
- Keeps 81.5-82.6% memory reuse at 13.8μs worst-case overhead
- Eliminating leakage required 75-90% lineage completeness; 90% suggested as deployment target
- A real LLM-SQL agent PoC: zero leaks over 9 round-trips, two KPI conflicts caught automatically
Positioned as a governance layer complementing source-level access control and supporting EU AI Act compliance; a feasibility demo, not production evidence.
More from Safety
- Human Review Halved in AI Repos: Researchers Propose "Comprehension Audits" for RSI — ronbodkin · 2026-10-09
- Researcher: open-weight risk analysis fixates on capability, ignores cost-per-attack — dhadfieldmenell · 2026-10-09
- New research: conflicting training values can make models' CoT contradict their answers — OwainEvans_UK · 2026-10-09
- Security principle: AI capability must never automatically confer authority — Ghost_Pilot_MD · 2026-10-09
- USA Today files federal lawsuit accusing OpenAI of training LLMs on copyrighted news — Polymarket · 2026-10-09
- AI coding agent leaked 13,000+ internal screenshots to a public GitHub repo — Arindam_1729 · 2026-10-09