Story · arXiv
MemLeak: Cross-User Semantic Leakage in Multi-Tenant AI Agent Memory (arXiv)
paper · Story page

Agents sharing one vector store for long-term memory can hand one user's memories to another through ordinary cosine-similarity retrieval, with no exploit involved. Non-adversarial leakage reaches 70-100% under pooled same-team retrieval, and contaminated responses often scored as helpful or more helpful than clean ones.
In plain words
- Researchers found that artificial intelligence assistants could reveal one user's saved information while answering someone else.
- They searched a shared collection for information with similar meanings, including information belonging to other users.
- Answers containing someone else's information often received ratings as helpful as, or better than, answers without it.
- Employers judging these assistants by helpful answers alone could overlook leaks of information between coworkers.
Appeared in
- Claude Code's Bash tool changed 12% of calls carrying code or escapes
Oct 07, 2026 · in the sections
Subscribe
Get the brief in your inbox
Pick daily, weekly, or both. Nothing is gated either way: every issue is on the site and in the feeds.
- Weekdays at 8:45am IST, one lead story and 6 to 9 items.
- Sundays, an argued synthesis rather than a recap.
- One click to leave, and quiet days say so in the subject line.
