Story · arXiv

MemLeak: Cross-User Semantic Leakage in Multi-Tenant AI Agent Memory (arXiv)

paper · Story page

Two people at separate desks query their own assistants. One open filing drawer stands between them, folders sorted by similarity. An arrow from the left desk reaches into the drawer and returns holding a folder that belongs to the right desk.

Agents sharing one vector store for long-term memory can hand one user's memories to another through ordinary cosine-similarity retrieval, with no exploit involved. Non-adversarial leakage reaches 70-100% under pooled same-team retrieval, and contaminated responses often scored as helpful or more helpful than clean ones.

In plain words

  • Researchers found that artificial intelligence assistants could reveal one user's saved information while answering someone else.
  • They searched a shared collection for information with similar meanings, including information belonging to other users.
  • Answers containing someone else's information often received ratings as helpful as, or better than, answers without it.
  • Employers judging these assistants by helpful answers alone could overlook leaks of information between coworkers.

Appeared in

Subscribe

Get the brief in your inbox

Pick daily, weekly, or both. Nothing is gated either way: every issue is on the site and in the feeds.

  • Weekdays at 8:45am IST, one lead story and 6 to 9 items.
  • Sundays, an argued synthesis rather than a recap.
  • One click to leave, and quiet days say so in the subject line.
How often

Weekdays 8:45am IST + Sundays. Unsubscribe in one click.

You're asking for The Agentic Brief by email at the cadence you picked. You can unsubscribe in one click from any issue, and your address is never sold or shared.