Files
agent/papers/items/2026-2605-14421-memlineage-lineage-guided-enforcement-for-llm-agent-memory.md
T
2026-07-10 18:01:44 +08:00

1.6 KiB

Paper: MemLineage: Lineage-Guided Enforcement for LLM Agent Memory


type: paper title: "MemLineage: Lineage-Guided Enforcement for LLM Agent Memory" authors: Ciyan Ouyang, Rui Hou year: 2026 venue: arXiv url: https://arxiv.org/abs/2605.14421 code_url: source: arxiv collected_at: 2026-07-08 published_at: 2026-05-14 updated_at: 2026-05-14 status: skimmed relevance: high topics:

  • agent-evaluation
  • computer-use
  • memory
  • tool-use methods:
  • cryptographic-provenance
  • derivation-lineage
  • sensitive-action-gate benchmarks:
  • custom-cross-session-memory-harness
  • AgentDojo-bridge models:

datasets:

  • cs.CR
  • cs.AI related_concepts:
  • memory-provenance
  • memory-poisoning related_jobs:

related_experiments:

  • KC-001-agent-memory-pilot related_projects:
  • learning/agent-memory collection_score: 17 collection_queries: agent-memory

One-line Takeaway

签名只能证明谁写入;敏感行动还必须检查当前理由是否沿派生链继承了不可信来源。

Pilot Skim

  • problem: 恶意外部内容可以经多次 memory derivation 被语义洗白,未来再触发敏感动作。
  • method: 为条目附加签名与 derivation DAG,把来源 trust 传播到 action gate。
  • evidence: 自定义 deterministic harness 的三类攻击中,只有 lineage 方案全部达到 0 ASR。
  • boundary: headline 是机制隔离 benchmark,不是完整公共 benchmark;未完成大规模 adaptive attack,且假设模型推理路径可信。

Used In