acceptodds
Under review as a conference paper at ICLR 2027

Hidden, Not Erased: Attention-Side Access Control for Compacted Agent Memory

Abstract

Compacting an agent's trajectory is usually treated as deletion: once older interactions are summarized, their exact contents stop influencing the model, even though they still exist in an archived tool result. This conflates two separable decisions, storage and visibility. We make visibility the object of control. Triggered Sparse Attention keeps raw pre-compaction spans archived and ineligible by default. A trigger decides whether they may be attended to at all; the model's own sparse indexer then chooses which hidden tokens to read, independently for each layer and decoding position. In the model-native form, opened evidence is never written back into the prompt. On Qwen3-4B with a native sparse indexer, in 1,000 fresh synthetic agent traces whose queried fact survives only in the archive, triggered opening answers 342 while a closed archive and random opening at a higher rate answer none, and with sixteen archived events it answers 123 against 14 for random opening at exactly its opening rate. Reusing DeepSeek-V3.2's pretrained sparse indexer without retraining hidden-token identity, archive access recovers 21 of 26 hidden details where summary-only memory recovers none. In two pre-registered replications on 512 fresh paired WebShop tasks each, with byte-identical prompts across arms, selective recall beats random access at similar archive volume (157 against 134, p=0.015; 163 against 132, p<0.001) and raises mean reward over indiscriminate access at 2.7 times less archive volume.

Then back it, or bet against it.

Related papers

Open the market on this paper to see 7 more related papers.