Elastic privacy memory keeps long term chat data safe based on social roles

EP-Mem: Elastic Privacy Memory for Social Relationship-Aware LLM Agents

Artificial Intelligence

Summary

Large language model agents can risk leaking private information when helping people communicate. The authors designed EP-Mem, a system that helps these agents remember information while respecting each user's privacy settings based on their social relationships. This system controls what details can be shared with whom, using rules set by the user. Their tests showed EP-Mem reduces privacy leaks significantly while still allowing good performance in remembering and sharing information appropriately.

What this means in practice

  • For ai developers: Build conversational AI agents that manage long-term user data privacy based on social context and user-configured rules.
  • For enterprise chat system teams: Enhance chat platforms to enforce privacy policies across user interactions by controlling information disclosure in multi-party sessions.

Authors

Fengzhou Sun, Yuan Zhang, Xintong Yu, Jinyao Yan

Abstract

Large language model (LLM) agents face critical privacy risks when acting as delegates in human-agent-human communication. To prevent such breaches, agents must understand users' social relationships and adhere to context-dependent social information disclosure boundaries. Current studies on agent memory privacy focus on instantaneous interactions, leaving the long-term relational disclosure problem unexplored. In this paper, we propose EP-Mem, an Elastic Privacy Memory architecture that reframes privacy as user-owned boundary control across social roles. EP-Mem introduces (1) token-level memory driven by user-configurable a privacy policy that stratifies persons and events, combining domain-level default circulation rules with fact-level whitelist/blacklist exceptions; and (2) a pluggable sidecar with a privacy engine that aligns disclosure controls with memory across summary, detail, and boundary granularities, enforced throughout generation, storage, and retrieval. We construct EP-Bench, to our knowledge the first long-term multi-party benchmark with cross-session correlated events for policy-conditioned relational disclosure. Experiments show that EP-Mem achieves 94.0% privacy classification accuracy, improves disclosure-permission judgment from 22% to 68%, and reduces privacy leakage by 75.6%, while maintaining retrieval performance and cross-benchmark generalization.