arXiv:cs.LG· Venkata M Sangaraju, Sudhir Vissa·· 4 小时前AI 评分46
面向企业 AI 智能体的血缘感知内存治理:派生门控的列级隐私访问控制框架
Lineage-Aware Memory Governance: A Derivation-Gated Framework for Privacy-Preserving Column-Level Access Control in Enterprise AI Agents
AI 导读
研究提出 Analytical Memory Unit(AMU),为每条缓存结果附加完整派生(血缘)图,只有请求者对其触及的每一列都有权限时才返回命中,从而在企业 AI 智能体共享内存中阻断派生数据的越权泄露。
正文
Abstract:Enterprise AI agents that share a memory store face two unaddressed risks: sensitive data can leak through legitimately computed results the requester could not derive, and departments can silently compute a same-named key performance indicator (KPI) through conflicting logic. Existing agent-memory systems (e.g., MemGPT, Zep, A-MEM) gate retrieval by content, ownership, and role, not derivation, missing a cached insight that embeds a forbidden column. We introduce the Analytical Memory Unit (AMU), a memory schema that attaches a full derivation (lineage) graph to every cached result, gated by a retrieval policy that serves a hit only when the requester is authorised for every column touched. Provided lineage recording is complete, we prove by construction that the policy blocks retrieval of results derived from a sensitive column outside the requester's permissions, at O(n) worst case -- a conditional design guarantee, not an empirical claim, that excludes derived features encoding sensitive information without naming their source. Eliminating measured leakage required 75-90% recorded lineage completeness, so we treat 90% as a conservative deployment target. Across six experiments, lineage-gated retrieval removes the 18.8-25.5% cross-department leakage naive content-gated memory suffers, keeping 81.5-82.6% of memory reuse at 13.8 microsecond worst-case overhead. A real-agent proof-of-concept with LLM-generated SQL is consistent with the guarantee: zero leaks over 9 round-trips, two conflicts caught automatically -- though a feasibility demonstration, not evidence of production viability. This offers a practical governance layer for shared agent memory, complementing source-layer access control and supporting EU AI Act compliance.
| Subjects: | Cryptography and Security (cs.CR); Artificial Intelligence (cs.AI); Computation and Language (cs.CL); Machine Learning (cs.LG) |
| Cite as: | arXiv:2610.07258 [cs.CR] |
| (or arXiv:2610.07258v1 [cs.CR] for this version) | |
| https://doi.org/10.48550/arXiv.2610.07258 arXiv-issued DOI via DataCite (pending registration) |
|
| Related DOI: | https://doi.org/10.1109/ACCESS.2026.3730363
DOI(s) linking to related resources |
Submission history
From: Venkata Manikanta Sangaraju [view email]
[v1]
Mon, 5 Oct 2026 18:56:56 UTC (784 KB)
来源:arXiv:cs.LG · arxiv.org