Unveiling Privacy Risks in LLM Agent Memory
2025/02/17 by Bo Wang, Weiyi He, Wang, Bo +11 · 34 citations
Computer Science · #Cloud Data Security Solutions #Security and Verification in Computing #Privacy-Preserving Technologies in Data
paper · pdf · doi:10.48550/arxiv.2502.13172
Abstract
Large Language Model (LLM) agents have become increasingly prevalent across various real-world applications. They enhance decision-making by storing private user-agent interactions in the memory module for demonstrations, introducing new privacy risks for LLM agents. In this work, we systematically investigate the vulnerability of LLM agents to our proposed Memory EXTRaction Attack (MEXTRA) under a black-box setting. To extract private information from memory, we propose an effective attacking prompt design and an automated prompt generation method based on different levels of knowledge about the LLM agent. Experiments on two representative agents demonstrate the effectiveness of MEXTRA. Moreover, we explore key factors influencing memory leakage from both the agent designer's and the attacker's perspectives. Our findings highlight the urgent need for effective memory safeguards in LLM agent design and deployment.
Cited by
- Isolated but Exposed: Persistence-Based Memory Extraction Attack on LLM Agents
- Agent Tools Orchestration Leaks More: Dataset, Benchmark, and Mitigation
- Agent Skills Matter: Inferring Proprietary Skills from Execution Trajectories
- Topology Matters: Measuring Memory Leakage in Multi-Agent LLMs
- Don't Trust Your Upstream: Exploiting LLM Multi-Agent System via Topology-Guided Adversarial Propagation
- An Empirical Study on the Security Vulnerabilities of GPTs
- A Longitudinal Measurement of Privacy Policy Evolution for Large Language Models
- Empowering Real-World: A Survey on the Technology, Practice, and Evaluation of LLM-driven Industry Agents
- MAGPIE: A benchmark for Multi-AGent contextual PrIvacy Evaluation
- Past, Present, and Future of Bug Tracking in the Generative AI Era
- Chain-of-Trigger: An Agentic Backdoor that Paradoxically Enhances Agentic Robustness
- PEAR: Planner-Executor Agent Robustness Benchmark
- AgentHub: A Registry for Discoverable, Verifiable, and Reproducible AI Agents
- A-MemGuard: A Proactive Defense Framework for LLM-Based Agent Memory
- Agentic Services Computing
- Meta-Policy Reflexion: Reusable Reflective Memory and Rule Admissibility for Resource-Efficient LLM Agent
- Network-Level Prompt and Trait Leakage in Local Research Agents
- Towards Aligning Personalized Conversational Recommendation Agents with Users' Privacy Preferences
- Privacy-Aware Decoding: Mitigating Privacy Leakage of Large Language Models in Retrieval-Augmented Generation
- A Survey on Agent Workflow -- Status and Future
- Tool Specifications Matter: Uncovering and Mitigating Safety Risks in AI Agents
- A Survey on Autonomy-Induced Security Risks in Large Model-Based Agents
- A Survey of LLM-Driven AI Agent Communication: Protocols, Security Risks, and Defense Countermeasures
- Comprehensive Vulnerability Analysis is Necessary for Trustworthy LLM-MAS
- LLM Agents Should Employ Security Principles
- MNC: Scope-Bound Semantic Declassification for Private LLM-Agent Communication
- Beyond Text: Unveiling Privacy Vulnerabilities in Multi-modal Retrieval-Augmented Generation
- A Survey on the Safety and Security Threats of Computer-Using Agents: JARVIS or Ultron?
- HUSH-Bench: Measuring Memory-Use Boundaries for Sensitive History in Conversational Agents
- Deployment-Time Memorization in Foundation-Model Agents
- From Agent Traces to Trust: A Survey of Evidence Tracing and Execution Provenance in LLM Agents
- MemPrivacy: Privacy-Preserving Personalized Memory Management for Edge-Cloud Agents
- DP-MemView: A Memory Interface for Attribute-Level Transcript Privacy in Long-Term LLM Agents
- From Human Memory to AI Memory: A Survey on Memory Mechanisms in the Era of LLMs
Related