acceptodds
Under review as a conference paper at ICLR 2027

Executable Memory with Authenticated Runtime Admission for Long-Term Agents

Abstract

Long-term agent memory becomes operational when stored instructions govern tool use. Retrieval-based systems ask language models both to select relevant memory and to reconstruct its authorized effect, coupling semantic judgment with security-sensitive execution. We introduce Executable Memory with Authenticated Runtime Admission (EMARA), a systems architecture that represents registered, authority-bearing memory as typed programs and mediates their use at runtime. EMARA separates learned semantic nomination from trusted, state-bound admission. The model nominates public program handles; a reference monitor evaluates current-state predicates and releases only actions bound to authenticated certificates. We evaluate EMARA on MemBind-Bench, a long-context benchmark spanning web policies, workspace boundaries, secret handling, atomic program composition, and time-scoped knowledge use. Comparisons with textual, retrieval, external-memory, and executable baselines show that separating nomination from admission enables reliable, state-consistent execution across diverse memory settings. Controlled studies isolate semantic nomination, stored program content, action realization, certificate verification, request wording, and backbone choice. Together, the results identify runtime admission, rather than retrieval alone, as the mechanism that enables authorized execution from long-term agent memory.

Then back it, or bet against it.

Related papers

Open the market on this paper to see 7 more related papers.