arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

MAPLE-Guard:多智能体系统中针对内存链接投毒的内存感知链接执行防御机制

MAPLE-Guard: Memory-Aware Link Enforcement Against Memory-Link Poisoning in Multi-Agent Systems

Wenjun Xiong, Yijin Zhou, Jiaqian Wang, Shangding Gu, Bo Tang, Zhiyu Li, Feiyu Xiong, Ying Wen, Muning Wen

arXiv 2608.00426首次发表:更新:

AI 中文总结

MAPLE-Guard通过在多智能体系统内存生命周期的关键环节设置防御关卡,大幅降低内存链接投毒攻击的成功率,提升多智能体防御成功率,填补了现有防御的空白。

AI 中文摘要

基于大语言模型(LLM)的多智能体系统(MAS)日益依赖持久的私有内存与共享内存来实现长程协调。这一内存层提升了系统的连续性,但也为攻击者提供了持久的攻击通道:投毒后的内存只需写入一次,即可在后续任务中被持续检索、提升至共享内存,并被其他智能体复用。一次恶意写入即可操控后续大量决策,污染从未接触原始攻击的智能体,且在危害发生时,无恶意消息穿过可见的通信边。此外,现有防御措施主要检查提示词、动作或通信边,可能遗漏那些在写入时内容看似良性、检索后才变得有害的攻击。我们提出内存感知传播与链接执行防御机制(Memory-Aware Propagation and Link Enforcement Guard,MAPLE-Guard),这是一种针对支持内存的多智能体系统的内存链接防御机制。MAPLE-Guard监控内存生命周期,在写入、检索、提升及跨智能体重用环节设置关卡,从而隔离风险内存、过滤不安全的检索操作,并在投毒的私有内存进入共享内存前将其拦截。在主要评估中,MAPLE-Guard在LongMemEval上将攻击成功率(ASR)从38.2%降至0.9%,在AppWorld上将ASR从34.7%降至0.2%;同时在相同基准上,将多智能体防御成功率(MDSR)从54.0%提升至74.3%,从42.5%提升至99.8%。这些结果表明,内存感知链接执行填补了提示词级和拓扑级防御留下的空白。代码可在以下链接获取:this https URL。

英文摘要

LLM-based multi-agent systems (MAS) increasingly rely on persistent private and shared memories for long-horizon coordination. This memory layer improves continuity, but it also gives attackers a durable channel: a poisoned memory can be written once, continuously retrieved in later tasks, promoted into shared memory, and reused by other agents. A single poisoned write can therefore steer many later decisions and contaminate agents that never saw the original attack, all while no malicious message crosses a visible communication edge at the moment of harm. Further, because existing safeguards mainly inspect prompts, actions, or communication edges, they can miss attacks whose content appears benign at write time but becomes harmful after retrieval. We introduce Memory-Aware Propagation and Link Enforcement Guard, MAPLE-Guard, a memory-link guard for memory-enabled MAS. MAPLE-Guard monitors the memory lifecycle and places gates at write, retrieval, promotion, and cross-agent reuse, so risky memories can be quarantined, unsafe retrievals filtered, and poisoned private memories blocked before they enter shared memory. In the main evaluation, MAPLE-Guard lowers attack success rate (ASR) from 38.2% to 0.9% on LongMemEval and from 34.7% to 0.2% on AppWorld; it also raises multi-agent defense success rate (MDSR) from 54.0% to 74.3% and from 42.5% to 99.8% on the same benchmarks. These results suggest that memory-aware link enforcement covers a gap left by prompt-level and topology-level defenses. Code is available at the link: https://github.com/xiong-wenjun/MAPLE-Guard.

Comments27 pages, 14 figures, 9 tables. Includes examples that may be misleading or harmful. Code: https://github.com/xiong-wenjun/MAPLE-Guard

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑