arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

Semantic-TVM:面向记忆增强与工具使用智能体的结构保持可信虚拟内存

Semantic-TVM: Structure-Preserving Trustworthy Virtual Memory for Memory-Augmented and Tool-Using Agents

Yu Li, Qikun Cai, Tao Huang, Chen Hou

arXiv 2609.15011首次发表:更新:

发表机构

MinJiang University(闽江学院)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

针对记忆增强与工具使用智能体的隐私泄露问题,提出结构保持的可信虚拟内存(TVM),通过语义级敏感跨度替换,在保持任务效用的同时降低暴露,实验验证了其有效性。

AI 中文摘要

记忆增强和工具使用的智能体在远程LLM处理检索到的记忆、工具操作和中间观察时,会暴露确切的私有值。单向掩码限制了直接暴露,但移除了可信执行所需的值,并可能通过后续观察泄露这些值。我们提出可信虚拟内存(TVM),一种闭环运行时,将确切值的状态保持在本地,同时向远程模型提供受保护的视图。在此单一运行时内,Rule-TVM用本地可恢复的句柄替换整个受保护字段,而Semantic-TVM则仅替换由可信本地模型预测的敏感片段,保留周围与任务相关的上下文。在Memory-EHR和Memory-RAP上跨两个提供商,跨度级投影恢复了在整字段替换下丢失的大部分EHR效用(DeepSeek上任务成功率84.17%对比52.33%),而测量到的暴露保持较低,工作流保持可执行。

英文摘要

Memory-augmented and tool-using agents expose exact private values when remote LLMs process retrieved memory, tool actions, and intermediate observations. One-way masking limits direct exposure but removes values needed for trusted execution and can leak them through later observations. We propose Trustworthy Virtual Memory (TVM), a closed-loop runtime that keeps exact-value state local while presenting a protected view to the remote model. Within this single runtime, Rule-TVM replaces whole protected fields with locally recoverable handles, and Semantic-TVM instead replaces only sensitive spans predicted by a trusted local model, preserving surrounding task-relevant context. On Memory-EHR and Memory-RAP across two providers, span-level projection recovers most of the EHR utility lost under whole-field replacement (Task Success 84.17% vs. 52.33% on DeepSeek) while measured exposure stays low and workflows remain executable.

CommentsWorking draft, 4 pages plus references; 4 figures. Submitted as a preprint

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑