Foundation-model agents are increasingly long-lived systems that remember users across interactions, making memorization an explicit deployment-time function rather than solely a property of model weights. Existing work addresses parametric memorization or audits fixed memory configurations, but does not characterize how memory-design choices jointly shape personalization utility, extraction risk, and deletion fidelity. We study this surface as deployment-time memorization, formulating agent memory as a privacy-utility frontier measured by Personalization Recall (PR) and Adversarial Extraction Rate (AER), and sweeping three memory-design knobs: summarization aggressiveness, retrieval breadth (k), and deletion mode. We further introduce the Forgetting Residue Score (FRS) to quantify whether deleted information remains recoverable from derived memory tiers. On LongMemEval, key-fact summarization reduces canary extraction by 76% on Gemma 3 12B and 64% on GPT-4o-mini while preserving nearly all personalization recall; critically, once content is compressed away, increasing k no longer restores leakage. The same compression, however, induces a deletion-fidelity failure: raw-only deletion leaves derived summary copies recoverable in approximately 20% of instances, and only full-pipeline purge or tombstone redaction drives worst-tier residue to zero. Together, these results establish that persistent agent memory must be evaluated as a first-class memorization mechanism -- assessed by what it helps agents recall, what it makes extractable, and what it can truly erase.
翻译:基础模型智能体正日益成为长期运行的交互系统,能够在多次交互中记住用户信息,这使得记忆成为明确的部署时功能,而不仅仅是模型权重的属性。现有研究关注参数化记忆或审计固定记忆配置,但未能描述记忆设计选择如何共同塑造个性化效用、提取风险与删除保真度。我们将这一维度定义为部署时记忆,将智能体记忆建模为以个性化召回率(PR)和对抗提取率(AER)衡量的隐私-效用前沿,并系统探索三个记忆设计参数:摘要生成激进程度、检索广度(k值)以及删除模式。我们进一步提出遗忘残差分数(FRS),以量化已删除信息是否仍可从衍生记忆层级中恢复。在LongMemEval上的实验表明,关键事实摘要生成使Gemma 3 12B的金丝雀提取率降低76%,GPT-4o-mini降低64%,同时几乎保持全部个性化召回率;关键在于,一旦内容被压缩消除,增大k值不再恢复数据泄露。然而,相同的压缩却导致删除保真度缺陷:仅原始数据删除使得衍生摘要副本在大约20%的实例中可恢复,只有全流水线清除或墓碑编辑才能使最差层级残差归零。综合而言,这些结果确立了持久性智能体记忆必须作为第一类记忆机制进行评估——通过其帮助智能体回忆的内容、使其可被提取的信息以及其真正能够擦除的数据来衡量。