arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2608.17148cs.CRcs.AI

上下文之前的授权:一种针对智能体系统中跨受众记忆泄露的模型无关受众边界

Authorization Before Context: A Model-Neutral Audience Boundary Against Cross-Audience Memory Leakage in Agentic Systems

Sibo Liu

首次发表
浏览论文内容

中文总结 AI 辅助

本研究针对智能体系统的跨受众记忆泄露问题,提出模型无关的受众边界方法,通过反单调授权规则确保未授权事实不进入上下文,在合成数据集上验证了其有效性。

中文摘要 AI 辅助

个人语言智能体从某一受众处学习到事实后,可能会在后续为另一受众组装的提示词中加入该事实。这种从记忆到上下文的步骤是一个攻击面:模糊或不一致的通道、跨受众窥探以及中毒记忆,都可能导致系统组装出包含与查询相关但未授权给当前查看者的事实的上下文。我们提出在上下文之前进行授权:在记忆到上下文的转换时应用单一的反单调受众成员规则。每个条目都带有其被记录时的受众;当前查看者集合从通道元数据中读取,若存在歧义则默认设为公开;仅当所有当前查看者都属于该条目记录时的受众时,该条目才被允许。我们证明,该规则使每个参与者都能实现跨通道回忆,同时通过排除而非模型行为,确保为较窄受众记录的内容不会传递给更广泛的受众,且中毒记忆无法扩大自身受众。该边界是对组装的精确上下文的模型无关不变量:在调用模型前,禁止的事实必须不存在。在合成的Contextual-Integrity套件上,我们的边界组装的上下文未包含任何禁止的事实,而无范围基线则按构造包含此类事实;我们进一步审计发现,所有读取路径均为失败关闭。该证据是初步的且基于合成数据。

英文摘要

A personal language agent learns a fact from one audience and may later place it in the prompt it assembles for another. This memory-to-context step is an attack surface: ambiguous or inconsistent channels, cross-audience prying, and poisoned memory can each cause the system to assemble context containing a fact relevant to the query yet unauthorized for the current viewers. We introduce authorization before context: a single, anti-monotone audience-membership rule applied at the memory-to-context transition. Each item carries the audience present when it was recorded; the current viewer set is read from channel metadata and falls back to public when ambiguous; and the item is admitted only when every current viewer already belonged to its audience. We prove that this rule gives every participant cross-channel recall while ensuring, by exclusion rather than by model behavior, that nothing recorded for a narrower audience reaches a broader one and that poisoned memory cannot widen its own audience. The boundary is a model-neutral invariant on the exact assembled context: a forbidden fact must be absent before the model is called. On a synthetic Contextual-Integrity suite, no forbidden fact entered the context our boundary assembled, whereas unscoped baselines included such facts by construction; we further audit that every read path fails closed. The evidence is preliminary and synthetic.

补充信息

↑