Fetching from the wire…
Agents2026-09-21 · source-backed
This paper argues privacy leakage is usually measured inside one component, conflating internal exposure with attacker-recoverable information. Modeling the whole chain from sensitive source through selection, assembly, execution, observation and extraction, storage labels alone didn't determine recoverability: memory targets are near-saturated, retrieval leakage is frequently partial, and tool-mediated leakage swings with observation surface, retrieval depth and provider behavior. A stratified semantic audit caught disclosures exact matching missed.
Each link below shares sources, entities, or timing with this story.
Li, Huo, and Johnson show that one-way message flow between agents produces neither mimicry nor solo behavior but an entirely novel dynamical state, at identical temperature settings. It's conceptual rather than quantitative, but the implication for orchestrator-worker fan-out...
arXiv 2608.11632 argues storage retention doesn't identify *authoritative* state: unmediated updates by models, tools, and background workers cause stale overwrites and self-authorizing privilege escalation. Untrusted components propose typed changes against an exact predecess...
arXiv 2609.20045 audits context compression with paired histories that share the same current answer, receive the same future update, then require different answers. A deterministic frontier selector scored 96/96 strict reveal accuracy on DeepSeek but 82/96 on GLM, a structure...
Recuris (arXiv 2608.24876) keeps a Working Memory tracking current task progress separate from an Experiential Memory of learned skills, so skill selection indexes against what the task needs now rather than the whole history. It improves 35 of 37 model-benchmark pairs, gains...
The attack needs no instruction, trigger, or retriever optimization, just plainly worded false assertions generated in one pass against a LongMemEval corpus. A four-stage screening pipeline that reaches 0.832 recall on indirect prompt injection rejected none of the poisoned me...
arXiv 2608.05906 keeps a dual-polarity memory of verified corrections and observed dead ends for Text-to-SQL repair: 66.34% to 69.79% on Spider, 47.35% to 48.44% on BIRD. Then the authors say the quiet part: paired analysis supports the Spider gain but is weak on BIRD, MERIT i...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.