Artificial intelligenceAgent securityDeveloper tools

Provenance-preserving long-horizon memory regression harness

Cross-stack tests that verify memory consolidation and retrieval cannot amplify low-authority observations into high-authority tool actions.

01

Thesis

Demonstrated

Generative Agents documents retrieval omissions and embellished memories in its reported simulation.

Inference

A portable regression harness may detect authority amplification across consolidators, retrievers, schemas, and model changes.

Why now

Current delta papers assert a memory-provenance threat and independently reproduce memory systems against simpler raw-turn RAG.

Binding constraint

The provenance attack paper is unaudited, cross-framework reproduction is absent, and no buyer, incident, product, patent, or procurement evidence has established a differentiated paid need.

02

Scorecard

evidence3/5
unexploredness1/5
technical4/5
operational3/5
value1/5
Prior-art position

Raw-history/RAG, framework memory stores, prompt-injection filters, tool authorization, and the PPMF mechanism are nearby. Patent/product/framework/procurement coverage is incomplete.

Risks
  • False blocking
  • Incomplete provenance labels
  • Benchmark-only attacks
  • Framework vendors can absorb the feature
  • Unknown buyer demand
03

Decisive experiment

Test

Run 100 benign and 100 matched adversarial multi-session traces across raw-turn RAG and three memory stacks; measure authority preservation, unauthorized actions, benign completion, contradiction recall, latency, and storage.

Kill criterion

Drop if no stack amplifies authority above raw history, or if a gate cannot reduce unauthorized high-risk actions 80% while preserving 95% benign completion.

04

Source evidence

1 papers