{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2025:BTZ3M4DCSM4J2R3VYSQ4BRPJ5E","short_pith_number":"pith:BTZ3M4DC","schema_version":"1.0","canonical_sha256":"0cf3b6706293389d4775c4a1c0c5e9e935df05f19aeaa05415cfd6f647a1001a","source":{"kind":"arxiv","id":"2502.13172","version":2},"attestation_state":"computed","paper":{"title":"Unveiling Privacy Risks in LLM Agent Memory","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.AI"],"primary_cat":"cs.CR","authors_text":"Bo Wang, Jiliang Tang, Pengfei He, Shenglai Zeng, Weiyi He, Yue Xing, Zhen Xiang","submitted_at":"2025-02-17T19:55:53Z","abstract_excerpt":"Large Language Model (LLM) agents have become increasingly prevalent across various real-world applications. They enhance decision-making by storing private user-agent interactions in the memory module for demonstrations, introducing new privacy risks for LLM agents. In this work, we systematically investigate the vulnerability of LLM agents to our proposed Memory EXTRaction Attack (MEXTRA) under a black-box setting. To extract private information from memory, we propose an effective attacking prompt design and an automated prompt generation method based on different levels of knowledge about "},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2502.13172","kind":"arxiv","version":2},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2025-02-17T19:55:53Z","cross_cats_sorted":["cs.AI"],"title_canon_sha256":"0adf05a09046bd43dceb89cdfe86364167249585bc85b5f4ef2e83eeb4e6a029","abstract_canon_sha256":"073c602eed459c057c2791172b447fb4ce4a6554c178cdfbfeec24c984012375"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T11:14:54.004602Z","signature_b64":"bl1aV3hklrbh8hVhUYCpVxU2dviTFNRRdVG7pIGaiMhLJ0kXJlp0ZHDAfV4VOrbSXZ3bzXZLViotcgjoxZzYAg==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"0cf3b6706293389d4775c4a1c0c5e9e935df05f19aeaa05415cfd6f647a1001a","last_reissued_at":"2026-07-05T11:14:54.004022Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T11:14:54.004022Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Unveiling Privacy Risks in LLM Agent Memory","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.AI"],"primary_cat":"cs.CR","authors_text":"Bo Wang, Jiliang Tang, Pengfei He, Shenglai Zeng, Weiyi He, Yue Xing, Zhen Xiang","submitted_at":"2025-02-17T19:55:53Z","abstract_excerpt":"Large Language Model (LLM) agents have become increasingly prevalent across various real-world applications. They enhance decision-making by storing private user-agent interactions in the memory module for demonstrations, introducing new privacy risks for LLM agents. In this work, we systematically investigate the vulnerability of LLM agents to our proposed Memory EXTRaction Attack (MEXTRA) under a black-box setting. To extract private information from memory, we propose an effective attacking prompt design and an automated prompt generation method based on different levels of knowledge about "},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2502.13172","kind":"arxiv","version":2},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2502.13172/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2502.13172","created_at":"2026-07-05T11:14:54.004102+00:00"},{"alias_kind":"arxiv_version","alias_value":"2502.13172v2","created_at":"2026-07-05T11:14:54.004102+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2502.13172","created_at":"2026-07-05T11:14:54.004102+00:00"},{"alias_kind":"pith_short_12","alias_value":"BTZ3M4DCSM4J","created_at":"2026-07-05T11:14:54.004102+00:00"},{"alias_kind":"pith_short_16","alias_value":"BTZ3M4DCSM4J2R3V","created_at":"2026-07-05T11:14:54.004102+00:00"},{"alias_kind":"pith_short_8","alias_value":"BTZ3M4DC","created_at":"2026-07-05T11:14:54.004102+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":11,"internal_anchor_count":0,"sample":[{"citing_arxiv_id":"2606.24535","citing_title":"Governed Shared Memory for Multi-Agent LLM Systems","ref_index":21,"is_internal_anchor":false},{"citing_arxiv_id":"2606.26627","citing_title":"Agents That Know Too Much: A Data-Centric Survey of Privacy in LLM Agents","ref_index":112,"is_internal_anchor":false},{"citing_arxiv_id":"2606.10173","citing_title":"Local Is Not a Sufficient Privacy Boundary: Governing OS-Integrated On-Device AI","ref_index":44,"is_internal_anchor":false},{"citing_arxiv_id":"2605.27825","citing_title":"MRMMIA: Membership Inference Attacks on Memory in Chat Agents","ref_index":26,"is_internal_anchor":false},{"citing_arxiv_id":"2503.21460","citing_title":"Large Language Model Agent: A Survey on Methodology, Applications and Challenges","ref_index":217,"is_internal_anchor":false},{"citing_arxiv_id":"2605.18762","citing_title":"ALDEN: Boosting Private Data Extraction from Retrieval-Augmented Generation Systems via Active Learning and Distribution Estimation","ref_index":100,"is_internal_anchor":false},{"citing_arxiv_id":"2605.17830","citing_title":"Remembering More, Risking More: Longitudinal Safety Risks in Memory-Equipped LLM Agents","ref_index":10,"is_internal_anchor":false},{"citing_arxiv_id":"2504.15965","citing_title":"From Human Memory to AI Memory: A Survey on Memory Mechanisms in the Era of LLMs","ref_index":155,"is_internal_anchor":false},{"citing_arxiv_id":"2507.21046","citing_title":"A Survey of Self-Evolving Agents: What, When, How, and Where to Evolve on the Path to Artificial Super Intelligence","ref_index":296,"is_internal_anchor":false},{"citing_arxiv_id":"2604.23338","citing_title":"A Systematic Survey of Security Threats and Defenses in LLM-Based AI Agents: A Layered Attack Surface Framework","ref_index":89,"is_internal_anchor":false},{"citing_arxiv_id":"2604.09747","citing_title":"ADAM: A Systematic Data Extraction Attack on Agent Memory via Adaptive Querying","ref_index":22,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/BTZ3M4DCSM4J2R3VYSQ4BRPJ5E","json":"https://pith.science/pith/BTZ3M4DCSM4J2R3VYSQ4BRPJ5E.json","graph_json":"https://pith.science/api/pith-number/BTZ3M4DCSM4J2R3VYSQ4BRPJ5E/graph.json","events_json":"https://pith.science/api/pith-number/BTZ3M4DCSM4J2R3VYSQ4BRPJ5E/events.json","paper":"https://pith.science/paper/BTZ3M4DC"},"agent_actions":{"view_html":"https://pith.science/pith/BTZ3M4DCSM4J2R3VYSQ4BRPJ5E","download_json":"https://pith.science/pith/BTZ3M4DCSM4J2R3VYSQ4BRPJ5E.json","view_paper":"https://pith.science/paper/BTZ3M4DC","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2502.13172&json=true","fetch_graph":"https://pith.science/api/pith-number/BTZ3M4DCSM4J2R3VYSQ4BRPJ5E/graph.json","fetch_events":"https://pith.science/api/pith-number/BTZ3M4DCSM4J2R3VYSQ4BRPJ5E/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/BTZ3M4DCSM4J2R3VYSQ4BRPJ5E/action/timestamp_anchor","attest_storage":"https://pith.science/pith/BTZ3M4DCSM4J2R3VYSQ4BRPJ5E/action/storage_attestation","attest_author":"https://pith.science/pith/BTZ3M4DCSM4J2R3VYSQ4BRPJ5E/action/author_attestation","sign_citation":"https://pith.science/pith/BTZ3M4DCSM4J2R3VYSQ4BRPJ5E/action/citation_signature","submit_replication":"https://pith.science/pith/BTZ3M4DCSM4J2R3VYSQ4BRPJ5E/action/replication_record"}},"created_at":"2026-07-05T11:14:54.004102+00:00","updated_at":"2026-07-05T11:14:54.004102+00:00"}