acceptodds
Under review as a conference paper at ICLR 2027

Disclosure Begets Disclosure: A Self-Reinforcing Privacy Loop in LLM Agents with Persistent Memory

Abstract

Large language model (LLM) agents increasingly use persistent memory to personalize responses across sessions, but the same mechanism may also facilitate the inference of users' personal attributes. We study how persistent memory affects such inference over repeated interactions. In multi-session simulations, a user agent with predefined personal attributes interacts with a support agent with or without persistent memory. To isolate the effect of memory-conditioned dialogue generation, both conditions are given the same accumulated interaction record at inference time. We find that persistent memory consistently increases personal-attribute inference accuracy across models and disclosure conditions, even when attributes are never stated directly. Removing only direct disclosures has little effect, whereas suppressing inferable user information substantially reduces inference but also eliminates much of the personalization benefit. By varying the amount of available memory and by branching interactions at different levels of accumulated memory, we further show that inference is driven by accumulated content rather than elapsed sessions, and that memory-conditioned responses elicit increasingly attribute-revealing information as memory grows. Together, these results show that privacy leakage under persistent memory is self-reinforcing and difficult to separate from the utility of personalization.

open until 14 Dec 2026

est. 32% chance this paper gets accepted at ICLR 2027.

Reject 68%Accept 32%

What do you think this paper will get?

All positions stay anonymous.

Related papers

Loading the map…

Discussion (0)

Sign in to comment.