MemLeak: Cross-User Semantic Leakage in Multi-Tenant AI Agent Memory

📅 2026-10-03
📈 Citations: 0
✨ Influential: 0
📄 PDF
🤖 AI Summary
This study addresses the privacy risks arising from cross-user semantic memory leakage when multi-tenant AI agents share vector stores. We formally define cross-user acceptability failure and quantify privacy vulnerabilities under both non-adversarial and adversarial retrieval settings. Through systematic evaluation using MiniLM dense retrieval, TF-IDF sparse retrieval, and cosine similarity, we propose a low-latency hard-ownership gating mechanism. Experimental results demonstrate that unprotected systems exhibit leakage rates of 70%–100% with response contamination scores reaching 5/5. The proposed hard-gating approach emerges as the sole effective mitigation strategy, restoring contamination scores to baseline levels (1.00/5) while introducing only 1.4 ms of additional latency, thereby achieving an optimal balance between security guarantees and real-time performance requirements.
📝 Abstract
Personal AI agents in enterprise multi-tenant deployments share a common vector store for long-term memory. Shared embedding spaces create a surface for cross-user memory leakage: a user's query can retrieve semantically adjacent memories belonging to another user through ordinary cosine-similarity retrieval, without any exploit. We formalize this as cross-user admissibility failure and evaluate it across six experiments, plus follow-up ablations, under both sparse (TF-IDF) and production-faithful (MiniLM-L6-v2) retrieval. Non-adversarial, incidental leakage reaches 70--100\% under pooled {same-team} retrieval; adversarially crafted memories achieve 90--100\% top-$k$ placement, exceeding weaker keyword-based attacker baselines, with score lifts of $+0.416$ to $+0.511$ under production-faithful dense retrieval (Config B); and end-to-end response contamination reaches 5.00/5 under a production retrieval path and 4.67/5 with Claude Sonnet~4.5, with contaminated responses often scoring as helpful or more helpful than clean ones, a gap validated against human judgment. Among three architectural mitigations, only hard post-retrieval ownership gating consistently restores the clean baseline (1.00/5) across {two generation models, at a measured latency overhead of roughly 1.4~ms per query.
Problem

Research questions and friction points this paper is trying to address.

cross-user memory leakage
multi-tenant AI agent
shared embedding space
semantic leakage
vector store
Innovation

Methods, ideas, or system contributions that make the work stand out.

Cross-user semantic leakage
Multi-tenant AI agent
Vector store memory
Adversarial retrieval
Ownership gating
🔎 Similar Papers
P
Priyanka Mudgal
Workday AI Research
K
Kai Zhao
Workday AI Research
G
Guilin Zhang
Workday AI Research
A
Andy Olsen
Workday AI Research
E
Ezekiel Miller
Workday AI Research
X
Xu Chu
Workday AI Research
A
Aletta Johanna Blanken
Workday AI Research