acceptodds
Under review as a conference paper at ICLR 2027

RevBound: Revocation Cuts for Transformed Agent Memory

Abstract

An agent reads an authorized memory fragment, compresses it into a plan, and caches that plan for a peer. Access is then revoked. The source disappears from retrieval, yet its derivative can still enter the next model call. RevBound treats this lifecycle as a path-coverage problem over execution provenance: a revocation cut must intersect every denied-source path after its last mutable transformation. The Object-Alignment Principle identifies when revocation evaluations protect the same output under the same relational source closure, policy version, and decision boundary. RevBound realizes such a cut at model-call admission with typed user–agent and agent–resource lineage, a linearizable policy fence, transitive parent closure, and an AllowedBundle-only invocation path. In 1,160 matched fixed-parent attacks spanning re-summarization, paraphrase, merging, and relay, retrieval-time filtering exposes 600 forbidden derivatives (51.7%); two independently implemented final-boundary serializers expose 56 (4.8%) and 36 (3.1%), while RevBound exposes none (one-sided 95% upper bound \(\leq0.26%\)). RevBound also records zero violations over 156,000 churned bundle reads and 1.8M fragment checks at 7.6 ms p95. On SWE-Coop it resolves 28.4\(\pm\)1.1% of issues, compared with 23.6\(\pm\)1.0% for shared vector memory, and a second model/tool stack reproduces the boundary-class gap, with trace-audited leaks falling from 55/300 to 1/300. Revocation for transforming agent memory must therefore be enforced on the model-admitted object, where complete lineage and non-bypassable routing turn source denial into descendant exclusion.

Then back it, or bet against it.

Related papers

Open the market on this paper to see 7 more related papers.