2606.06054v1 Jun 04, 2026 cs.AI

유사성을 넘어: 개인 AI 에이전트를 위한 신뢰성 있는 메모리 검색

Beyond Similarity: Trustworthy Memory Search for Personal AI Agents

Yechao Zhang
Yechao Zhang
Citations: 20
h-index: 2
Lipeng He
Lipeng He
Citations: 34
h-index: 3
Jiawen Zhang
Jiawen Zhang
Citations: 24
h-index: 4
Kejia Chen
Kejia Chen
Citations: 126
h-index: 4
Jian Liu
Jian Liu
Citations: 126
h-index: 4
Xiaohu Yang
Xiaohu Yang
Citations: 9
h-index: 2
Jiachen Ma
Jiachen Ma
Citations: 173
h-index: 4
Tianwei Zhang
Tianwei Zhang
Citations: 23
h-index: 4
Ruoxi Jia
Ruoxi Jia
Citations: 699
h-index: 9
Yang Hu
Yang Hu
Citations: 43
h-index: 4

개인 AI 에이전트는 세션 간 지속적인 맞춤화를 제공하기 위해 점점 더 장기 메모리에 의존하고 있습니다. 그러나 기존의 메모리 파이프라인은 주로 의미적 유사성에 기반합니다. 즉, 현재 쿼리와 관련된 메모리 데이터를 검색하여 모델 컨텍스트에 주입합니다. 이는 중요한 신뢰성 격차를 야기하는데, 왜냐하면 의미적으로 관련 있는 메모리가 맥락상 부적절할 수 있으며, 이로 인해 도메인 간 정보 유출, 아첨, 도구 사용 방식의 변화 또는 메모리 기반 탈옥과 같은 문제가 발생할 수 있습니다. 본 논문에서는 개인 AI 에이전트에서 메모리 검색을 신뢰 경계로서 연구합니다. A-Mem, Mem0, MemOS와 같은 대표적인 에이전트 메모리 프레임워크를 OpenClaw라는 실제 개인 에이전트 환경(지속적인 상태 및 도구 사용 기능 포함)과 함께 평가했습니다. 우리의 결과는 장기 메모리가 단순한 유틸리티 레이어가 아니라, 에이전트가 작업을 해석하고 행동을 수행하는 방식을 근본적으로 변화시킬 수 있는 강력한 제어 채널이며, 따라서 위에서 언급된 위험에 매우 취약하다는 것을 보여줍니다. 이러한 취약점을 완화하기 위해, 우리는 9백만 개의 파라미터와 35.1MB의 작은 용량으로 신뢰성 있는 메모리 검색을 위한 경량화되고 배포 가능한 메모리 플러그인인 MemGate를 제안합니다. MemGate는 벡터 메모리 저장소와 핵심 LLM 사이에 삽입되며, LLM 수정, 메모리 데이터베이스 재작성 또는 추론 시 LLM 판단이 필요하지 않습니다. MemGate는 쿼리에 따라 조건을 설정하는 신경망 게이트를 사용하여 후보 메모리 표현에 적용하고, 단순한 유사성 검색을 작업 기반의 메모리 수용으로 전환합니다. 여러 가지 주류 메모리 프레임워크, 실제 에이전트 환경 및 다양한 LLM 백본에서 MemGate는 메모리 유발 위험을 줄이는 동시에 장기 메모리의 유용성을 유지합니다.

Original Abstract

Personal AI agents increasingly rely on long-term memory to provide persistent personalization across sessions. However, existing memory pipelines are largely driven by semantic similarity: memory data close to the current query is retrieved and injected into the model context. This creates a critical trustworthiness gap, since a semantically related memory may still be contextually inappropriate, leading to threats such as cross-domain leakage, sycophancy, tool-call drift, or memory-induced jailbreaks. In this paper, we study memory search as a trust boundary in personal AI agents. We evaluate representative agentic memory frameworks, including A-Mem, Mem0, and MemOS, together with OpenClaw, a real-world personal-agent environment with persistent state and tool-use capability. Our results show that long-term memory is not merely a utility layer, but a durable control channel that can reshape how agents interpret tasks and execute actions, leaving them highly susceptible to the aforementioned threats. To mitigate these vulnerabilities, we propose MemGate, a lightweight and deployable memory plug-in for trustworthy memory search, with only 9M parameters and a 35.1MB footprint. MemGate is inserted between the vector memory store and the backbone LLM, requiring no LLM modification, memory-database rewriting, or inference-time LLM judge. It applies a query-conditioned neural gate to candidate memory representations, turning raw similarity search into task-conditioned memory admission. Across multiple mainstream memory frameworks, real-world agent settings, and diverse LLM backbones, MemGate reduces memory-induced threats while preserving long-term memory utility.

0 Citations
0 Influential
4.5 Altmetric
22.5 Score
Original PDF

No Analysis Report Yet

This paper hasn't been analyzed by Gemini yet.

Log in to request an AI analysis.

댓글

댓글을 작성하려면 로그인하세요.

아직 댓글이 없습니다. 첫 번째 댓글을 남겨보세요!