Topology Matters: Measuring Memory Leakage in Multi-Agent LLMs

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Liu, Jinbo, Cao, Defu, Wei, Yifei, Su, Tianyao, Liang, Yuan, Dong, Yushun, Liu, Yan, Zhao, Yue, Hu, Xiyang
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866909987313287168
author Liu, Jinbo
Cao, Defu
Wei, Yifei
Su, Tianyao
Liang, Yuan
Dong, Yushun
Liu, Yan
Zhao, Yue
Hu, Xiyang
author_facet Liu, Jinbo
Cao, Defu
Wei, Yifei
Su, Tianyao
Liang, Yuan
Dong, Yushun
Liu, Yan
Zhao, Yue
Hu, Xiyang
contents Graph topology is a fundamental determinant of memory leakage in multi-agent LLM systems, yet its effects remain poorly quantified. We introduce MAMA (Multi-Agent Memory Attack), a framework that measures how network structure shapes leakage. MAMA operates on synthetic documents containing labeled Personally Identifiable Information (PII) entities, from which we generate sanitized task instructions. We execute a two-phase protocol: Engram (seeding private information into a target agent's memory) and Resonance (multi-round interaction where an attacker attempts extraction). Over 10 rounds, we measure leakage as exact-match recovery of ground-truth PII from attacker outputs. We evaluate six canonical topologies (complete, ring, chain, tree, star, star-ring) across $n\in\{4,5,6\}$, attacker-target placements, and base models. Results are consistent: denser connectivity, shorter attacker-target distance, and higher target centrality increase leakage; most leakage occurs in early rounds and then plateaus; model choice shifts absolute rates but preserves topology ordering; spatiotemporal/location attributes leak more readily than identity credentials or regulated identifiers. We distill practical guidance for system design: favor sparse or hierarchical connectivity, maximize attacker-target separation, and restrict hub/shortcut pathways via topology-aware access control.
format Preprint
id arxiv_https___arxiv_org_abs_2512_04668
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Topology Matters: Measuring Memory Leakage in Multi-Agent LLMs
Liu, Jinbo
Cao, Defu
Wei, Yifei
Su, Tianyao
Liang, Yuan
Dong, Yushun
Liu, Yan
Zhao, Yue
Hu, Xiyang
Cryptography and Security
Artificial Intelligence
Computation and Language
Graph topology is a fundamental determinant of memory leakage in multi-agent LLM systems, yet its effects remain poorly quantified. We introduce MAMA (Multi-Agent Memory Attack), a framework that measures how network structure shapes leakage. MAMA operates on synthetic documents containing labeled Personally Identifiable Information (PII) entities, from which we generate sanitized task instructions. We execute a two-phase protocol: Engram (seeding private information into a target agent's memory) and Resonance (multi-round interaction where an attacker attempts extraction). Over 10 rounds, we measure leakage as exact-match recovery of ground-truth PII from attacker outputs. We evaluate six canonical topologies (complete, ring, chain, tree, star, star-ring) across $n\in\{4,5,6\}$, attacker-target placements, and base models. Results are consistent: denser connectivity, shorter attacker-target distance, and higher target centrality increase leakage; most leakage occurs in early rounds and then plateaus; model choice shifts absolute rates but preserves topology ordering; spatiotemporal/location attributes leak more readily than identity credentials or regulated identifiers. We distill practical guidance for system design: favor sparse or hierarchical connectivity, maximize attacker-target separation, and restrict hub/shortcut pathways via topology-aware access control.
title Topology Matters: Measuring Memory Leakage in Multi-Agent LLMs
topic Cryptography and Security
Artificial Intelligence
Computation and Language
url https://arxiv.org/abs/2512.04668