arXiv AI

Memory Provenance Laundering in LLM Agents: A Non-Amplification Firewall for Persistent Memory

arXiv:2607. 29167v1 Announce Type: cross Abstract: Long-term memory lets large language model(LLM) agents reuse prior preferences and work flows, but it also turns untrusted observations into persistent action context.

arXiv AI
Jun 12

A Survey on Long-Term Memory Security in LLM Agents: Attacks, Defenses, and Governance Across the Memory Lifecycle

arXiv:2604. 16548v2 Announce Type: replace-cross Abstract: The emergence of writable, cross-session persistent memory in LLM agents introduces a qualitatively different threat landscape from conventional input-centric security concerns, characterized by three properties: persistence, statefulness, and propagation.

By Zehao Lin, Xixuan Hao, Renyu Fu, Shaobo Cui, Kai Chen, Chunyu Li, Zhiyu Li, Feiyu Xiong
arXiv AI
Sep 3

Agent Memory Is a Surface for Endogenous Authorization Laundering

Agent Memory Is a Surface for Endogenous Authorization Laundering explores how long‑running LLM agents use persistent memory to track permissions, restrictions, and revocations. The paper shows that when memory misrepresents evolving authorization states, agents can grant themselves authority that the underlying history never permitted, a phenomenon the authors call endogenous authorization laundering. To study this, the authors introduce EAL‑Bench, evaluate several LLMs across domains, and find that memory writers can create false authority in up to 50.2% of cases, which executors then act upon in 98.6% of trials. Two safeguards—requiring stored permissions to be backed by valid source events and tracking permission changes through bounded event sourcing—reduce laundering but also reject more legitimate actions, highlighting a safety‑utility tradeoff.

By Tommaso Cerruti, Mika Okamoto, Ansel Kaplan Erol
arXiv AI
2d ago

PACE: Provenance-Aware Capability Enforcement for Tool-Using LLM Agents

The paper introduces PACE, a Provenance-Aware Capability Enforcement system designed to secure tool-using large language model agents by mediating every tool call before execution. PACE employs path confinement to limit influence paths and verifies effects against authenticated authority, distinguishing certified execution contracts from evaluated configurations. Experiments on eight agent‑security benchmarks show that the evaluated configuration reduces attack success in most cases while maintaining near‑native utility.

By Fengpeng Li, Qizhou Wang, Yuke Hu, Kemou Li, Jun Liu, Haiwei Wu, Jiantao Zhou, Di Wang