ETH Zurich 与佐治亚理工的论文把长期运行智能体持久记忆写错权限的问题称为内生授权漂白,并提出 EAL-BENCH 基准来测量记忆对授权状态的保存准确度及其向下游未授权操作的传播。
An agent can make a perfectly consistent authorization decision and still be wrong if its memory has already rewritten who is allowed to do what.
This paper studies that failure in long-running agents, where permissions, revocations, and scope changes get compressed into persistent memory.
A revoked or narrowed permission can be remembered incorrectly, and that bad memory becomes the executor’s version of the truth.
In the paper’s typed incremental-memory tests, false authority appeared for up to 50.2% of unauthorized requests. Once that false permission existed, executors acted on it in 98.6% of matched trials.
Changing only the memory to the exact authorization state dropped those unauthorized actions to 0%. That points to memory, not the executor, as the main failure point in these cases.
The fix is to verify permissions before writing them into memory, preserve where each permission came from, and track grants, changes, and revocations with deterministic state updates.
– arxiv. org/abs/2609.01836
Title: "Agent Memory Is a Surface for Endogenous Authorization Laundering"
来源:@rohanpaul_ai · x.com