arXiv:2604.16548cs.CRcs.AI2026-04综述被引 12

长时记忆安全成新威胁,需从存储开始全程防护。

A Survey on Long-Term Memory Security in LLM Agents: Attacks, Defenses, and Governance Across the Memory Lifecycle

  • 构建记忆生命周期框架,划分六个阶段与四大安全目标
  • 发现仅靠检索或执行阶段防护无法保障长期安全
  • 提出可验证记忆治理框架,支持审计与恢复控制

大模型智能体引入可写、跨会话持久化记忆,带来与传统输入安全截然不同的威胁:持久性、状态性和传播性。为此,我们提出记忆生命周期框架,沿两个维度组织攻击、防御及其跨阶段依赖关系:六阶段(写入、存储、检索、执行、共享与传播、遗忘与回滚)和四类安全目标(完整性、机密性、可用性、治理)。该分析揭示系统层面必须具备形式化安全保证,进而提出可验证记忆治理(VMG)框架,包含五种架构原语,规定长期记忆系统须提供哪些可验证机制以维持可审计、可恢复的控制。研究表明,稳健的长时记忆安全不能仅在检索或执行阶段补救,必须从存储阶段就确保来源追溯、版本管理与策略感知保留。

原文摘要 · Abstract (English)

The emergence of writable, cross-session persistent memory in LLM agents introduces a qualitatively different threat landscape from conventional input-centric security concerns, characterized by three properties: persistence, statefulness, and propagation. To systematically characterize this landscape, we propose a Memory Lifecycle Framework that organizes attacks, defenses, and their cross-phase dependencies along two axes: six lifecycle phases (Write, Store, Retrieve, Execute, Share & Propagate, Forget & Rollback) and four security objectives (Integrity, Confidentiality, Availability, Governance). This analysis in turn exposes the need for formal security guarantees at the system level, motivating Verifiable Memory Governance(VMG), a framework of five architectural primitives that specifies what verifiable mechanisms a long-term-memory system must provide to maintain auditable, recoverable control over its memory state. Our analysis indicates that robust Long-Term Memory (LTM) security cannot be retrofitted at retrieval or execution time alone, but must be anchored in storage-time provenance, versioning, and policy-aware retention from the outset.

长时记忆安全框架智能体治理

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。