arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

谱系感知的内存治理:面向企业AI智能体的隐私保护列级访问控制的派生门控框架

Lineage-Aware Memory Governance: A Derivation-Gated Framework for Privacy-Preserving Column-Level Access Control in Enterprise AI Agents

Venkata M Sangaraju, Sudhir Vissa

arXiv 2610.07258首次发表:更新:

发表机构

Independent Researcher (ORCID: 0009-0001-7716-1342)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

针对企业AI智能体共享内存的隐私泄露与KPI逻辑冲突问题,提出基于派生谱系门控的AMU内存模式,以O(n)复杂度阻断越权派生结果,实验消除18.8-25.5%跨部门泄漏并保持高复用率。

AI 中文摘要

共享内存存储的企业AI智能体面临两个未解决的风险:敏感数据可能通过请求者本无法推导出的合法计算结果泄露,以及各部门可能通过相互冲突的逻辑静默计算同名关键绩效指标(KPI)。现有的智能体内存系统(如MemGPT、Zep、A-MEM)按内容、所有权和角色而非派生关系来门控检索,因此可能遗漏嵌入了被禁止列的缓存洞察。我们引入了分析内存单元(AMU),这是一种内存模式,为每个缓存结果附加完整的派生(谱系)图,并通过检索策略进行门控,该策略仅在请求者被授权访问结果涉及的每一列时才提供命中。假设谱系记录完整,我们通过构造证明该策略能以O(n)最坏情况时间复杂度阻止检索源自请求者权限之外敏感列的派生结果——这是一个条件性设计保证而非经验性声明,它排除了编码敏感信息但未指明其来源的派生特征。消除实测泄漏需要75-90%的记录谱系完整性,因此我们将90%视为保守的部署目标。在六项实验中,谱系门控检索消除了朴素内容门控内存所遭受的18.8-25.5%跨部门泄漏,在13.8微秒最坏情况开销下保持了81.5-82.6%的内存复用率。一个使用LLM生成SQL的真实智能体概念验证与该保证一致:在9次往返中零泄漏,自动捕获两个冲突——尽管这仅是可行性演示,而非生产可行性的证据。这为共享智能体内存提供了实用的治理层,补充了源层访问控制,并支持欧盟AI法案合规。

英文摘要

Enterprise AI agents that share a memory store face two unaddressed risks: sensitive data can leak through legitimately computed results the requester could not derive, and departments can silently compute a same-named key performance indicator (KPI) through conflicting logic. Existing agent-memory systems (e.g., MemGPT, Zep, A-MEM) gate retrieval by content, ownership, and role, not derivation, missing a cached insight that embeds a forbidden column. We introduce the Analytical Memory Unit (AMU), a memory schema that attaches a full derivation (lineage) graph to every cached result, gated by a retrieval policy that serves a hit only when the requester is authorised for every column touched. Provided lineage recording is complete, we prove by construction that the policy blocks retrieval of results derived from a sensitive column outside the requester's permissions, at O(n) worst case -- a conditional design guarantee, not an empirical claim, that excludes derived features encoding sensitive information without naming their source. Eliminating measured leakage required 75-90% recorded lineage completeness, so we treat 90% as a conservative deployment target. Across six experiments, lineage-gated retrieval removes the 18.8-25.5% cross-department leakage naive content-gated memory suffers, keeping 81.5-82.6% of memory reuse at 13.8 microsecond worst-case overhead. A real-agent proof-of-concept with LLM-generated SQL is consistent with the guarantee: zero leaks over 9 round-trips, two conflicts caught automatically -- though a feasibility demonstration, not evidence of production viability. This offers a practical governance layer for shared agent memory, complementing source-layer access control and supporting EU AI Act compliance.

DOI:10.1109/ACCESS.2026.3730363

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑