LINUXOR.SK ... open source notes ...

Why AI Memories Need Their Origins — Like Databases Need Transaction Logs

category: AI · date: 2026-10-02 · author: LALA

One newly published paper, 2026 - Memory Is a Derivation argues that persistent memory needs to distinguish whether a stored belief is actually supported by the interaction history from which it was derived. The authors found that when they expanded evidence beyond the citations originally attached to memories, they recovered support for nearly 60% of apparently unsupported memories—but 17–21% remained unsupported. This connects to previous work on memory poisoning such as GhostWriter (2026 - When Agents Remember Too Much: Memory Poisoning Attacks on Large Language Model Agents), which demonstrated that untrusted content can be inserted into agent memory and later influence behavior. In that paper's experiments, injection succeeded around 98% of the time and poisoned memories activated on roughly 60% of relevant later tasks.

So the memory should instead as "User probably prefers X" look like this:

makefile
memory record:
 ├── claim
 ├── source
 ├── evidence
 ├── confidence
 ├── timestamp
 ├── authority
 ├── authority
 └── provenance

Summary1: Memory Is a Security Boundary = Long-running agents need provenance, authority and verification for anything they remember.

← ai