arXiv AI By Sibo Liu

Authorization Before Context: A Model-Neutral Audience Boundary Against Cross-Audience Memory Leakage in Agentic Systems

Read the original on arXiv AI →

The paper proposes an "authorization before context" rule to prevent cross‑audience memory leakage in personal language agents. Each memory item is tagged with the audience that recorded it, and when assembling context for a new audience, the system only includes items whose original audience fully overlaps the current viewers. The authors prove that this rule guarantees that no fact recorded for a narrower audience can appear in a broader one, and they demonstrate its effectiveness on a synthetic Contextual‑Integrity benchmark.

Machine-generated by The Flow from the publisher's headline and feed description — not written or checked by a human. The full article lives at arXiv AI.

arXiv AI
4d ago

Audience-Bound Persistent Memory: Authorization Across the Memory Lifecycle

The paper introduces Audience‑Bound Persistent Memory, a system that tracks the audience of each memory item and enforces authorization throughout the memory lifecycle. Each item carries the audience present at recording, and derived items are partitioned or suppressed based on the intersection of source audiences, expanding only through explicit grants. The authors implement the approach in two reference architectures—a flat store and a relationship graph—and evaluate it on 10,000 multi‑party histories, showing that no forbidden items entered any context while unscoped retrieval exposed forbidden items in 82% of cases, and that entitled recall matched policy‑equivalent baselines and outperformed unscoped retrieval by 0.30 Recall@5.

By Sibo Liu
Hugging Face Trending Papers
Aug 3

MNC: Scope-Bound Semantic Declassification for Private LLM-Agent Communication

Multi-agent large language model (LLM) systems can expose protected state through internal messages, tool arguments, logs, and persistent memory even when their public outputs appear innocuous. Existing privacy prompts, redaction methods, and source-level access controls restrict surface content or data access, but do not specify what a legitimately informed agent should disclose or how that disclosure may be reused downstream.

arXiv Machine Learning
Sep 3

Context Inference Attacks Without Jailbreaks

The paper investigates privacy risks in agentic AI systems that assemble sensitive data into a hidden context before responding. It introduces context‑inference attacks, a security game that evaluates how well attackers can recover this hidden context under varying levels of knowledge and indirect delivery. Experiments show that even with controls such as instructions not to disclose, logit suppression, and context dilution, agents can leak significant contextual information, achieving high success rates across multiple attack settings.

By Prince Jha, Samuele Poppi, Nils Lukas