No Attacker Needed: Unintentional Cross-User Contamination in Shared-State LLM Agents

Fuente: arXiv
Guardado en:
Detalles Bibliográficos
Autores principales: Yang, Tiankai, Li, Jiate, Nian, Yi, Dong, Shen, Xu, Ruiyao, Rossi, Ryan, Ding, Kaize, Zhao, Yue
Formato: Preprint
Publicado: 2026
Materias:
Acceso en línea:
Etiquetas: Agregar Etiqueta
Sin Etiquetas, Sea el primero en etiquetar este registro!
_version_ 1866914439163281408
author Yang, Tiankai
Li, Jiate
Nian, Yi
Dong, Shen
Xu, Ruiyao
Rossi, Ryan
Ding, Kaize
Zhao, Yue
author_facet Yang, Tiankai
Li, Jiate
Nian, Yi
Dong, Shen
Xu, Ruiyao
Rossi, Ryan
Ding, Kaize
Zhao, Yue
contents LLM-based agents increasingly operate across repeated sessions, maintaining task states to ensure continuity. In many deployments, a single agent serves multiple users within a team or organization, reusing a shared knowledge layer across user identities. This shared persistence expands the failure surface: information that is locally valid for one user can silently degrade another user's outcome when the agent reapplies it without regard for scope. We refer to this failure mode as unintentional cross-user contamination (UCC). Unlike adversarial memory poisoning, UCC requires no attacker; it arises from benign interactions whose scope-bound artifacts persist and are later misapplied. We formalize UCC through a controlled evaluation protocol, introduce a taxonomy of three contamination types, and evaluate the problem in two shared-state mechanisms. Under raw shared state, benign interactions alone produce contamination rates of 57--71%. A write-time sanitization is effective when shared state is conversational, but leaves substantial residual risk when shared state includes executable artifacts, with contamination often manifesting as silent wrong answers. These results indicate that shared-state agents need artifact-level defenses beyond text-level sanitization to prevent silent cross-user failures.
format Preprint
id arxiv_https___arxiv_org_abs_2604_01350
institution arXiv
publishDate 2026
record_format arxiv
spellingShingle No Attacker Needed: Unintentional Cross-User Contamination in Shared-State LLM Agents
Yang, Tiankai
Li, Jiate
Nian, Yi
Dong, Shen
Xu, Ruiyao
Rossi, Ryan
Ding, Kaize
Zhao, Yue
Computation and Language
Artificial Intelligence
Cryptography and Security
LLM-based agents increasingly operate across repeated sessions, maintaining task states to ensure continuity. In many deployments, a single agent serves multiple users within a team or organization, reusing a shared knowledge layer across user identities. This shared persistence expands the failure surface: information that is locally valid for one user can silently degrade another user's outcome when the agent reapplies it without regard for scope. We refer to this failure mode as unintentional cross-user contamination (UCC). Unlike adversarial memory poisoning, UCC requires no attacker; it arises from benign interactions whose scope-bound artifacts persist and are later misapplied. We formalize UCC through a controlled evaluation protocol, introduce a taxonomy of three contamination types, and evaluate the problem in two shared-state mechanisms. Under raw shared state, benign interactions alone produce contamination rates of 57--71%. A write-time sanitization is effective when shared state is conversational, but leaves substantial residual risk when shared state includes executable artifacts, with contamination often manifesting as silent wrong answers. These results indicate that shared-state agents need artifact-level defenses beyond text-level sanitization to prevent silent cross-user failures.
title No Attacker Needed: Unintentional Cross-User Contamination in Shared-State LLM Agents
topic Computation and Language
Artificial Intelligence
Cryptography and Security
url https://arxiv.org/abs/2604.01350