Divided Focus: Separated Memory Spaces and Default-Deny Context Triage for LLM Context Management

Fuente: Zenodo
Saved in:
Bibliographic Details
Main Author: Phan, Ivan "HiP"
Format: Recurso digital
Language:English
Published: Zenodo 2026
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866901337595183104
author Phan, Ivan "HiP"
author_facet Phan, Ivan "HiP"
contents <p>This paper proposes an architecture for LLM context management that separates commands and data into distinct memory spaces (L1 command, L2 active data, L3 reference storage) with default-deny triage: all incoming content enters the data tier by default and must pass through evaluation and summarisation gates before promotion to the command tier. The architecture addresses both prompt injection vulnerability and context degradation as consequences of the same architectural feature: the undifferentiated context window. Two triage modes are specified: a security-first mode (L3-by-default with two-gate promotion) and a performance-optimised mode (platform triage).<br>The paper identifies a verification inversion where unmanaged context structurally penalises fact-checking, reframes the entanglement problem from weight-level disentanglement to contextual mode-setting, and grounds the gate mechanism in peer-reviewed empirical work on task-frame shift and adversarial robustness. Native Memory Paper 2 in the series. Builds on Strategic Forgetting (Paper 1) and findings from the Confidence Curriculum series.</p>
format Recurso digital
id zenodo_https___doi_org_10_5281_zenodo_19353247
institution Zenodo
language eng
publishDate 2026
publisher Zenodo
record_format zenodo
spellingShingle Divided Focus: Separated Memory Spaces and Default-Deny Context Triage for LLM Context Management
Phan, Ivan "HiP"
LLM architecture
prompt injection
context management
memory separation
command-data separation
default-deny triage
verification inversion
provenance-based triage
context degradation
AI security
<p>This paper proposes an architecture for LLM context management that separates commands and data into distinct memory spaces (L1 command, L2 active data, L3 reference storage) with default-deny triage: all incoming content enters the data tier by default and must pass through evaluation and summarisation gates before promotion to the command tier. The architecture addresses both prompt injection vulnerability and context degradation as consequences of the same architectural feature: the undifferentiated context window. Two triage modes are specified: a security-first mode (L3-by-default with two-gate promotion) and a performance-optimised mode (platform triage).<br>The paper identifies a verification inversion where unmanaged context structurally penalises fact-checking, reframes the entanglement problem from weight-level disentanglement to contextual mode-setting, and grounds the gate mechanism in peer-reviewed empirical work on task-frame shift and adversarial robustness. Native Memory Paper 2 in the series. Builds on Strategic Forgetting (Paper 1) and findings from the Confidence Curriculum series.</p>
title Divided Focus: Separated Memory Spaces and Default-Deny Context Triage for LLM Context Management
topic LLM architecture
prompt injection
context management
memory separation
command-data separation
default-deny triage
verification inversion
provenance-based triage
context degradation
AI security
url https://doi.org/10.5281/zenodo.19353247