{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2026:CTWKKUVTKGIQ5YNR7GTDP6NUFE","short_pith_number":"pith:CTWKKUVT","schema_version":"1.0","canonical_sha256":"14eca552b351910ee1b1f9a637f9b429235c39ef19738715e5d702f60305d6d1","source":{"kind":"arxiv","id":"2605.27825","version":1},"attestation_state":"computed","paper":{"title":"MRMMIA: Membership Inference Attacks on Memory in Chat Agents","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.LG"],"primary_cat":"cs.CR","authors_text":"Kai Chen, Tianhao Wang, Yan Pang","submitted_at":"2026-05-27T01:31:40Z","abstract_excerpt":"Membership inference attacks (MIAs) test whether a target data record belongs to a system's private data, and have become a standard tool to measure privacy leakage in machine learning systems. Prior work has primarily focused on training corpora or retrieval databases. However, MIAs against agent memory have received less attention, even though such memory can contain sensitive user-agent interactions, retrieved facts, and user preferences. Therefore, in this work, we focus on chat agent memory MIAs, where an adversary infers whether a candidate memory unit belongs to the chat agent's memory "},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2605.27825","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2026-05-27T01:31:40Z","cross_cats_sorted":["cs.LG"],"title_canon_sha256":"baaa1af6e4adad200f9ae4e9214c0a3ccba5be7435d66c626527914131b9bfbe","abstract_canon_sha256":"15489d7593bb7a545880a2f9fcc70d2c2064d890b9fb5cc1df87c1aa42c9acb2"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-05-28T01:04:49.744890Z","signature_b64":"p6V58TkHk4RnlOe/cGI3jkfFDbn5nK5/aa8hlI98RR/e66/lDgQ+YNp24jPt1ZdDiZa4pHkZCyZNm7koLGBsCw==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"14eca552b351910ee1b1f9a637f9b429235c39ef19738715e5d702f60305d6d1","last_reissued_at":"2026-05-28T01:04:49.744509Z","signature_status":"signed_v1","first_computed_at":"2026-05-28T01:04:49.744509Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"MRMMIA: Membership Inference Attacks on Memory in Chat Agents","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.LG"],"primary_cat":"cs.CR","authors_text":"Kai Chen, Tianhao Wang, Yan Pang","submitted_at":"2026-05-27T01:31:40Z","abstract_excerpt":"Membership inference attacks (MIAs) test whether a target data record belongs to a system's private data, and have become a standard tool to measure privacy leakage in machine learning systems. Prior work has primarily focused on training corpora or retrieval databases. However, MIAs against agent memory have received less attention, even though such memory can contain sensitive user-agent interactions, retrieved facts, and user preferences. Therefore, in this work, we focus on chat agent memory MIAs, where an adversary infers whether a candidate memory unit belongs to the chat agent's memory "},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2605.27825","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2605.27825/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2605.27825","created_at":"2026-05-28T01:04:49.744565+00:00"},{"alias_kind":"arxiv_version","alias_value":"2605.27825v1","created_at":"2026-05-28T01:04:49.744565+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2605.27825","created_at":"2026-05-28T01:04:49.744565+00:00"},{"alias_kind":"pith_short_12","alias_value":"CTWKKUVTKGIQ","created_at":"2026-05-28T01:04:49.744565+00:00"},{"alias_kind":"pith_short_16","alias_value":"CTWKKUVTKGIQ5YNR","created_at":"2026-05-28T01:04:49.744565+00:00"},{"alias_kind":"pith_short_8","alias_value":"CTWKKUVT","created_at":"2026-05-28T01:04:49.744565+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":0,"internal_anchor_count":0,"sample":[]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/CTWKKUVTKGIQ5YNR7GTDP6NUFE","json":"https://pith.science/pith/CTWKKUVTKGIQ5YNR7GTDP6NUFE.json","graph_json":"https://pith.science/api/pith-number/CTWKKUVTKGIQ5YNR7GTDP6NUFE/graph.json","events_json":"https://pith.science/api/pith-number/CTWKKUVTKGIQ5YNR7GTDP6NUFE/events.json","paper":"https://pith.science/paper/CTWKKUVT"},"agent_actions":{"view_html":"https://pith.science/pith/CTWKKUVTKGIQ5YNR7GTDP6NUFE","download_json":"https://pith.science/pith/CTWKKUVTKGIQ5YNR7GTDP6NUFE.json","view_paper":"https://pith.science/paper/CTWKKUVT","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2605.27825&json=true","fetch_graph":"https://pith.science/api/pith-number/CTWKKUVTKGIQ5YNR7GTDP6NUFE/graph.json","fetch_events":"https://pith.science/api/pith-number/CTWKKUVTKGIQ5YNR7GTDP6NUFE/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/CTWKKUVTKGIQ5YNR7GTDP6NUFE/action/timestamp_anchor","attest_storage":"https://pith.science/pith/CTWKKUVTKGIQ5YNR7GTDP6NUFE/action/storage_attestation","attest_author":"https://pith.science/pith/CTWKKUVTKGIQ5YNR7GTDP6NUFE/action/author_attestation","sign_citation":"https://pith.science/pith/CTWKKUVTKGIQ5YNR7GTDP6NUFE/action/citation_signature","submit_replication":"https://pith.science/pith/CTWKKUVTKGIQ5YNR7GTDP6NUFE/action/replication_record"}},"created_at":"2026-05-28T01:04:49.744565+00:00","updated_at":"2026-05-28T01:04:49.744565+00:00"}