Shared agent memory can leak information across enterprise users

Controlled experiments found that semantic retrieval frequently surfaced another user’s memories, while hard ownership filtering prevented downstream contamination.

Industry
Priyanka Mudgal · Kai Zhao · Guilin Zhang · Andy Olsen · Ezekiel Miller · Xu Chu · +1 more

Workday AI Research

Research Digest··3 min read
Mudgal et al.

The authors formalized cross-user admissibility failure, where a memory is relevant to a query but not authorized for the querying user.

Why this paper

From Workday AI Research

In one line

Shared vector stores in multi-tenant AI agents cause cross-user memory leakage via semantic similarity, even without intent.

What we could check

  • ·No code link found
  • ·No weights link found
  • ·No dataset link found
  • ·No compute details found
  • ✓Limitations stated by the authors
  • ✓Reports numbers on named benchmarks (5 benchmarks)

Observed from the paper text and links we have. Absence here means we did not find it, not that it does not exist.

§

Research Digest

Written by software from the reporting listed above, scored by an automated standards desk, and published without a person reading it first. If something here is wrong, tell the editor and it will be put right.