Inferring Hidden User Models from the Behavior of Personalized LLM Agents
cs.CR
Submitted: 2026-09-03
Updated: 2026-09-03
Comments: 19 pages, 6 figures, and 5 tables
Code: https://github.com/langchain-ai/langmem
License: http://arxiv.org/licenses/nonexclusive-distrib/1.0/
Terminology
Sources
- User-LLM: Efficient LLM Contextualization with User Embeddings
- Mem0: Building Production-Ready AI Agents with Scalable Long-Term Memory
- Deployment-Time Memorization in Foundation-Model Agents
- ADAM: A Systematic Data Extraction Attack on Agent Memory via Adaptive Querying
- The Sum Leaks More Than Its Parts: Compositional Privacy Risks and Mitigations in Multi-Agent Collaboration
- Zep: A Temporal Knowledge Graph Architecture for Agent Memory
- PersonaMem-v2: Towards Personalized Intelligence via Learning Implicit User Personas and Agentic Memory
- Qwen3 Technical Report
- LLM-PBE: Assessing Data Privacy in Large Language Models
- Imprompter: Tricking LLM Agents into Improper Tool Use
- When Agents Learn to Be You: Benchmarking Privacy Leakage, Impersonation Risk, and Defenses in Persona Skills
- Spore: Efficient and Training-Free Privacy Extraction Attack on LLMs via Inference-Time Hybrid Probing
- Isolated but Exposed: Persistence-Based Memory Extraction Attack on LLM Agents
- Behavioral Privacy Leakage in Agentic Negotiation: Formalizing and Mitigating Inference Attacks via Randomized Policies
- PrivacyPeek: Auditing What LLM-Based Agents Acquire, Not Just What They Say
- Beyond Jailbreaking: Auditing Contextual Privacy in LLM Agents
- Dependency-Aware Privacy for Multi-turn Agents
Related papers
- SoK: AI-Augmented Binary Reversing
- Relaxed Sender Anonymity for CBDC Interbank Settlement: A Zero-Knowledge Approach on Permissioned EVM
- Calibration-Family Overfit: Why Trusted Sabotage Monitors Don't Transfer Across Lineages
- Efficient Fuzzy PSI under One-Sided Assumptions
- Sealing the Audit-Runtime Gap for LLM Skills
- Token Composition: A Graph Based on EVM Logs