该记住什么,该透露什么:面向对话智能体的隐私感知记忆
What to Remember, What to Reveal: Privacy-Aware Memory for Conversational Agents
AI总结:
该研究针对对话智能体的隐私风险,提出SP-Mem隐私感知记忆架构,通过全生命周期隐私设计实现更强个性化并减少不必要隐私暴露,还构建了相关基准。
AI中文摘要:
长期记忆使个性化对话智能体能够在多轮会话中保留用户信息。然而,现有的记忆架构主要针对效用进行优化,却忽略了不必要存储和重用个人身份信息(PII)等隐私属性的风险。解决个性化记忆中的隐私风险颇具挑战性,因为单纯移除敏感值可能会损害系统效用。因此,记忆智能体的隐私保护应覆盖敏感值的整个生命周期,而非仅对单个记录进行清理。为填补这一空白,我们提出了经清理的隐私映射记忆(SP-Mem),这是一种隐私感知的记忆架构,它将记忆效用与精确隐私值的暴露解耦。SP-Mem 提供了完整的生命周期隐私设计:从原始用户输入中识别并分离敏感信息,将清理后的内容和精确隐私值存储在独立结构中,并根据任务需求和用户同意选择性检索隐私值。我们还提出了一个隐私感知记忆基准,该基准联合评估响应质量、隐私行为和推理成本。在多个基于大语言模型(LLM)的智能体上进行的大量实验表明,SP-Mem 在实现更强个性化的同时,减少了不必要的隐私暴露。代码和数据可在该 https URL 获取。
英文摘要:
Long-term memory enables personalized conversational agents to retain user information across sessions. However, existing memory architectures primarily optimize for utility while neglecting the risks of unnecessarily storing and reusing private attributes such as personally identifiable information (PII). Addressing privacy risks in personalized memory is challenging because simply removing sensitive values can undermine system utility. Therefore, privacy protection for memory agents should govern the full life cycle of sensitive values rather than only sanitizing individual records. To address this gap, we introduce Sanitized Privacy-Mapped Memory (SP-Mem), a privacy-aware memory architecture that decouples memory utility from exact private-value exposure. SP-Mem provides a full life-cycle privacy design that identifies and separates sensitive information from raw user inputs, stores sanitized content and exact private values in isolated structures, and selectively retrieves private values based on task requirements and user consent. We further introduce a privacy-aware memory benchmark that jointly evaluates response quality, privacy behavior, and inference cost. Extensive experiments across multiple LLM-based agents show that SP-Mem achieves stronger personalization while reducing unnecessary privacy exposure. Code and data are available at https://github.com/Jensassss/SP-Mem.