When Stale Constraints Go Unchecked: Budgeted Verification Failures in Inherited Agent Memory
cs.IR, cs.AI, cs.CL
Submitted: 2026-08-26
Updated: 2026-08-28
Comments: 41 pages, 3 figures, 18 tables. v3: adds four prospectively frozen, externally deposited experiments (interleaved replication with a repaired control; content-free freshness cue; ten-model cross-organisation panel; budget sweep and target-blind allocation rules); abstract, figures and limitations rewritten; the four original runs unchanged. Data and code at Zenodo: doi:10.5281/zenodo.22147784
License: http://creativecommons.org/licenses/by/4.0/
The gist: Provenance links keep the evidence behind an inherited belief reachable; an agent with a verification budget must still choose which links to inspect.
Terminology
Abstract
Provenance links keep the evidence behind an inherited belief reachable; an agent with a verification budget must still choose which links to inspect. We study a consolidated memory that states a decision constraint and whose source record has since been superseded by a record that withdraws it: provenance is immutable, the current record has changed, and the memory is stale. In a controlled six-memory scenario with a budget of two records, sixteen language models rarely re-verified a constraint that read as settled: they inspected its provenance path in about one episode in five and, once the constraint had been superseded, produced stale-consistent decisions in 77.3%, 74.7% and 74.7% of episodes across a primary run, a replication and a held-out domain. Re-assigning one of the same two slots to the critical path removed most of them: +74.0, +72.7 and +61.3 points (positive in every model), +80.7 in a prospectively frozen interleaved replication with a repaired non-critical control, and +62.0 on a panel of 10 models from 9 organisations; a corrected re-run of the held-out scenario gave +73.3. The forced-critical policy uses experimenter knowledge of the critical path: it quantifies how much stale-decision risk the same budget can recover and is not a scheduler. Two further deposited experiments locate the failure and a remedy: in this store the constraint's path is selected in 17.0% of episodes at two slots and 88.7% at four of six (above uniform allocation), and at two slots a one-sentence, target-blind rule (prefer memories that state a limit on a candidate direction) moved the agent's own allocation onto the constraint's path and recovered the oracle contrast on decisions (+89.3 points) where that constraint limits the tempting action, while a content-free freshness cue did not materially redirect allocation and a content-matched control rule changed neither selection nor decisions.
Sources
- STALE: Can LLM Agents Know When Their Memories Are No Longer Valid?
- Governance Decay: How Context Compaction Silently Erases Safety Constraints in Long-Horizon LLM Agents
- From Untrusted Input to Trusted Memory: A Systematic Study of Memory Poisoning Attacks in LLM Agents
- Inference-Time Budget Control for LLM Search Agents
- Selection Integrity for LLM Graph Memory: An Accumulability Criterion for Information-Flow-Blind Retrieval
- Omission Constraints Decay While Commission Constraints Persist in Long-Context LLM Agents
- Evaluating Memory in LLM Agents via Incremental Multi-Turn Interactions
- Failing to Falsify: Evaluating and Mitigating Confirmation Bias in Language Models
- Auditing Provenance Sensitivity in LLM Agent Action Selection
- BAGEN: Are LLM Agents Budget-Aware?
- Securing LLM-Agent Long-Term Memory Against Poisoning: Non-Malleable, Origin-Bound Authority with Machine-Checked Guarantees
- Supersede: Diagnosing and Training the Memory-Update Gap in LLM Agents
- Zep: A Temporal Knowledge Graph Architecture for Agent Memory
- Reliable Post-Retrieval Assembly for Agent Memory: Separating Evidence Extraction from Policy Execution
- When Does Belief-Based Agent Memory Help? Reliability-Conditional Updating and Provenance-Capped Poisoning Defense
- From Recall to Forgetting: Benchmarking Long-Term Memory for Personalized Agents
- AllocBench: Measuring Online Tool Allocation Capability in LLM Agents
- From Agent Traces to Trust: A Survey of Evidence Tracing and Execution Provenance in LLM Agents
- MemEvoBench: Benchmarking Safety Risks from Memory Misevolution in LLM Agents
- Temporal Validity in Retrieval Memory: Eliminating Stale-Fact Errors for AI Agents over Evolving Knowledge
Related papers
- The Price of Isolation: Estimating the Ecosystem Cost of Symmetric Two-Sided A/B Testing
- SCAR: Semantic Continuity-Aware Retrieval for Efficient Context Expansion in RAG
- MixLoRA-DSI: Dynamically Expandable Mixture-of-LoRA Experts for Rehearsal-Free Generative Retrieval over Dynamic Corpora
- RRCM: Ranking-Driven Retrieval over Collaborative and Meta Memories for LLM Recommendation
- Right Family, Wrong Skill: Evaluating Risk Exposure in Agent Skill Retrieval
- UltRAG: a Universal Simple Scalable Recipe for Knowledge Graph RAG