MemLeak: Cross-User Semantic Leakage in Multi-Tenant AI Agent Memory
This study addresses the privacy risks arising from cross-user semantic memory leakage when multi-tenant AI agents share vector stores. We formally define cross-user acceptability failure and quantify privacy vulnerabilities under both non-adversarial and adversarial retrieval settings. Through systematic evaluation using MiniLM dense retrieval, TF-IDF sparse retrieval, and cosine similarity, we propose a low-latency hard-ownership gating mechanism. Experimental results demonstrate that unprotected systems exhibit leakage rates of 70%–100% with response contamination scores reaching 5/5. The proposed hard-gating approach emerges as the sole effective mitigation strategy, restoring contamination scores to baseline levels (1.00/5) while introducing only 1.4 ms of additional latency, thereby achieving an optimal balance between security guarantees and real-time performance requirements.