{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2026:SLIDP7KMD43MDHCWB6HHZ2W2CI","short_pith_number":"pith:SLIDP7KM","schema_version":"1.0","canonical_sha256":"92d037fd4c1f36c19c560f8e7ceada12077d6abf27af064f91c6fb899636add2","source":{"kind":"arxiv","id":"2606.29788","version":1},"attestation_state":"computed","paper":{"title":"MemLeak: Diagnosing Information Leaks in Multimodal Agent Memory","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":[],"primary_cat":"cs.LG","authors_text":"Chao Zhang, Kuan Wang","submitted_at":"2026-06-29T05:07:02Z","abstract_excerpt":"When a multimodal AI agent is asked to forget a fact, current memory systems usually delete the text entry and report success. We find that the fact can remain recoverable from retained user images, including images tagged to entirely different facts, because VLMs use implicit visual cues at inference time. We introduce the Information Provenance Graph (IPG), a taxonomy that classifies memory representations by deletion affordance. The IPG reveals that deletion fails through multiple channels. Our benchmark, MemLeak, measures this across a deletion cascade: direct probing of deletion-capable s"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2606.29788","kind":"arxiv","version":1},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.LG","submitted_at":"2026-06-29T05:07:02Z","cross_cats_sorted":[],"title_canon_sha256":"3484477d1c5e377b27565e45a86f6b7e9e91a559f43ad1876fd15d877ae6e14b","abstract_canon_sha256":"a7fd37e98bb701f282e8ca5c772a280c58c2bf0407f0447c6b7d327c6c0a2637"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-06-30T02:17:35.342935Z","signature_b64":"34+PI/YCW0Vpem9vcAF2KkERJisVhkDkLgkYvt+V6COgFEiXzGG/p2r4MYKgfECdU36+Iz04fWTZAz/EypZkDg==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"92d037fd4c1f36c19c560f8e7ceada12077d6abf27af064f91c6fb899636add2","last_reissued_at":"2026-06-30T02:17:35.342207Z","signature_status":"signed_v1","first_computed_at":"2026-06-30T02:17:35.342207Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"MemLeak: Diagnosing Information Leaks in Multimodal Agent Memory","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":[],"primary_cat":"cs.LG","authors_text":"Chao Zhang, Kuan Wang","submitted_at":"2026-06-29T05:07:02Z","abstract_excerpt":"When a multimodal AI agent is asked to forget a fact, current memory systems usually delete the text entry and report success. We find that the fact can remain recoverable from retained user images, including images tagged to entirely different facts, because VLMs use implicit visual cues at inference time. We introduce the Information Provenance Graph (IPG), a taxonomy that classifies memory representations by deletion affordance. The IPG reveals that deletion fails through multiple channels. Our benchmark, MemLeak, measures this across a deletion cascade: direct probing of deletion-capable s"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2606.29788","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2606.29788/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2606.29788","created_at":"2026-06-30T02:17:35.342330+00:00"},{"alias_kind":"arxiv_version","alias_value":"2606.29788v1","created_at":"2026-06-30T02:17:35.342330+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2606.29788","created_at":"2026-06-30T02:17:35.342330+00:00"},{"alias_kind":"pith_short_12","alias_value":"SLIDP7KMD43M","created_at":"2026-06-30T02:17:35.342330+00:00"},{"alias_kind":"pith_short_16","alias_value":"SLIDP7KMD43MDHCW","created_at":"2026-06-30T02:17:35.342330+00:00"},{"alias_kind":"pith_short_8","alias_value":"SLIDP7KM","created_at":"2026-06-30T02:17:35.342330+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":0,"internal_anchor_count":0,"sample":[]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/SLIDP7KMD43MDHCWB6HHZ2W2CI","json":"https://pith.science/pith/SLIDP7KMD43MDHCWB6HHZ2W2CI.json","graph_json":"https://pith.science/api/pith-number/SLIDP7KMD43MDHCWB6HHZ2W2CI/graph.json","events_json":"https://pith.science/api/pith-number/SLIDP7KMD43MDHCWB6HHZ2W2CI/events.json","paper":"https://pith.science/paper/SLIDP7KM"},"agent_actions":{"view_html":"https://pith.science/pith/SLIDP7KMD43MDHCWB6HHZ2W2CI","download_json":"https://pith.science/pith/SLIDP7KMD43MDHCWB6HHZ2W2CI.json","view_paper":"https://pith.science/paper/SLIDP7KM","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2606.29788&json=true","fetch_graph":"https://pith.science/api/pith-number/SLIDP7KMD43MDHCWB6HHZ2W2CI/graph.json","fetch_events":"https://pith.science/api/pith-number/SLIDP7KMD43MDHCWB6HHZ2W2CI/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/SLIDP7KMD43MDHCWB6HHZ2W2CI/action/timestamp_anchor","attest_storage":"https://pith.science/pith/SLIDP7KMD43MDHCWB6HHZ2W2CI/action/storage_attestation","attest_author":"https://pith.science/pith/SLIDP7KMD43MDHCWB6HHZ2W2CI/action/author_attestation","sign_citation":"https://pith.science/pith/SLIDP7KMD43MDHCWB6HHZ2W2CI/action/citation_signature","submit_replication":"https://pith.science/pith/SLIDP7KMD43MDHCWB6HHZ2W2CI/action/replication_record"}},"created_at":"2026-06-30T02:17:35.342330+00:00","updated_at":"2026-06-30T02:17:35.342330+00:00"}