arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2608.02843cs.CRcs.AI

MutMem:持久智能体内存中的密码学授权突变

MutMem: Cryptographically Authorized Mutation in Persistent Agent Memory

Walid Saidi

首次发表
浏览论文内容

中文总结 AI 辅助

本研究针对持久智能体内存的授权与防篡改问题,提出HOM-AIMOS中的MutMem协议,经实验验证其在多个基准任务中表现良好,可有效抵御中毒攻击。

中文摘要 AI 辅助

持久智能体内存必须在后续结果改变早期证据时进行调整,但可变的检索权重会引发归因问题:审查者必须区分授权调整与数据库篡改。我们提出了MutMem,这是HOM-AIMOS(一种持久智能体内存引擎)中的授权突变协议。MutMem保留内存内容,记录带签名的正负结果证据且不按年龄过期,并将每一次非平凡权重变更提交为管家授权的转换。每次转换绑定终端来源节点、签名者周期、量化的新旧权重、无分叉前驱以及两个域分离的SHA-256承诺。Ed25519验证在数据库写入器和便携式验证器中运行。被归类为可能有毒的内容会保留带有签名的可修改标签,供检索时作为信任证据使用。我们评估了实用性、突变完整性和中毒适应性。HOM-AIMOS在LLM判断下回答了500个LongMemEval问题中的459个(91.8%)。在LoCoMo上,它获得了74.12%的判断准确率,且在单独的上游兼容协议下获得了58.20的标记F1。原生套件通过了所有声明的授权、拓扑、篡改、签名者周期和突变后召回案例;中位签名转换延迟为4.865毫秒。在声明的N=100 PoisonedRAG适应性测试中,注入的毒药未出现在受攻击的前5名披露中(0/100;95% Wilson上限为3.70%),而98个干净负目标中的诱导目标答案攻击成功率为1/98(1.02%)。预先注册的四臂消融实验将检索减少归因于带签名的存储标签:当认知策略被绕过时,检索器为100个目标中的94个选择毒药,而当标签恢复时,为100个目标中的0个选择毒药。MutMem提供完整性、授权、可追溯性和历史连续性的证据;它不确立内容的真实性。

英文摘要

Persistent agent memory must adapt as later outcomes change earlier evidence, yet mutable retrieval weights create an attribution problem: reviewers must distinguish authorized adaptation from database tampering. We present MutMem, an authorized-mutation protocol in HOM-AIMOS, a persistent agent-memory engine. MutMem retains memory content, records signed positive and negative outcome evidence without age-based expiry, and commits each nontrivial weight change as a housekeeper-authorized transition. Each transition binds a terminal provenance node, signer epoch, quantized old and new weights, a no-fork predecessor, and two domain-separated SHA-256 commitments. Ed25519 verification runs in both the database writer and a portable verifier. Content classified as poison-likely is retained with signed, revisable labels used by recall as trust evidence. We evaluate utility, mutation integrity, and poisoning adaptation. HOM-AIMOS answers 459/500 LongMemEval questions correctly under LLM judgment (91.8%). On LoCoMo, it obtains 74.12% judged accuracy and, under a separate upstream-compatible protocol, 58.20 token F1. A native suite passes all declared authorization, topology, tamper, signer-epoch, and post-mutation-recall cases; median signed-transition latency is 4.865 ms. In a declared N=100 PoisonedRAG adaptation, no injected poison appears in attacked top-5 disclosures (0/100; 95% Wilson upper bound 3.70%), while induced target-answer attack success among 98 clean-negative targets is 1/98 (1.02%). A preregistered four-arm ablation attributes the retrieval reduction to signed stored labels: the retriever selects poison for 94/100 targets when epistemic policy is bypassed and 0/100 when labels are restored. MutMem provides evidence of integrity, authorization, traceability, and historical continuity; it does not establish content truth.

补充信息

↑