[
    {
        "id": "osp-16309",
        "type": "article-journal",
        "title": "MemLeak: Cross-User Semantic Leakage in Multi-Tenant AI Agent Memory",
        "author": [
            {
                "family": "Mudgal",
                "given": "Priyanka"
            },
            {
                "family": "Zhao",
                "given": "Kai"
            },
            {
                "family": "Zhang",
                "given": "Guilin"
            },
            {
                "family": "Olsen",
                "given": "Andy"
            },
            {
                "family": "Miller",
                "given": "Ezekiel"
            },
            {
                "family": "Chu",
                "given": "Xu"
            },
            {
                "family": "Blanken",
                "given": "Aletta Johanna"
            }
        ],
        "URL": "https://omanscience.com/en/articles/memleak-cross-user-semantic-leakage-in-multi-tenant-ai-agent-memory",
        "language": "en",
        "issued": {
            "date-parts": [
                [
                    2026
                ]
            ]
        },
        "abstract": "Personal AI agents in enterprise multi-tenant deployments share a common vector store for long-term memory. Shared embedding spaces create a surface for cross-user memory leakage: a user's query can retrieve semantically adjacent memories belonging to another user through ordinary cosine-similarity retrieval, without any exploit. We formalize this as cross-user admissibility failure and evaluate it across six experiments, plus follow-up ablations, under both sparse (TF-IDF) and production-faithful (MiniLM-L6-v2) retrieval. Non-adversarial, incidental leakage reaches 70--100\\% under pooled {same-team} retrieval; adversarially crafted memories achieve 90--100\\% top-$k$ placement, exceeding weaker keyword-based attacker baselines, with score lifts of $+0.416$ to $+0.511$ under production-faithful dense retrieval (Config B); and end-to-end response contamination reaches 5.00/5 under a production retrieval path and 4.67/5 with Claude Sonnet~4.5, with contaminated responses often scoring as helpful or more helpful than clean ones, a gap validated against human judgment. Among three architectural mitigations, only hard post-retrieval ownership gating consistently restores the clean baseline (1.00/5) across {two generation models, at a measured latency overhead of roughly 1.4~ms per query."
    }
]