Story · arXiv

Agent Memory Is a Surface for Endogenous Authorization Laundering (arXiv)

paper · Story page

A washing machine in a laundromat. Stamped and signed paper slips go in on the left. Blank slips with only a checkmark come out on the right and fall into a filing cabinet drawer.

Persistent memory can record permissions the interaction history never granted, and a later agent acts on them with no attacker involved. On EAL-Bench, memory writers created false authority for up to 50.2% of unauthorized requests and executors acted on it in 98.6% of trials; provenance-backed permissions and bounded event sourcing substantially reduce it.

In plain words

  • Researchers found that stored artificial intelligence memories can invent permissions that users never granted.
  • A later system may trust the false record and take an unauthorized action without any outside attacker.
  • Requiring every stored permission to link to a valid source greatly reduced the problem.
  • Organizations using long-running automation need permission records that preserve where each authorization came from.

Appeared in

Subscribe

Get the brief in your inbox

Pick daily, weekly, or both. Nothing is gated either way: every issue is on the site and in the feeds.

  • Weekdays at 8:45am IST, one lead story and 6 to 9 items.
  • Sundays, an argued synthesis rather than a recap.
  • One click to leave, and quiet days say so in the subject line.
How often

Weekdays 8:45am IST + Sundays. Unsubscribe in one click.

You're asking for The Agentic Brief by email at the cadence you picked. You can unsubscribe in one click from any issue, and your address is never sold or shared.