Session
Trustworthy Context Is Untrusted By Default
Structured memory is a compact injection surface. If an agent reads context that says "always use the production database" and acts on it, the consequences are real. This talk presents a trust architecture for stored agent context: server-generated preambles that warn agents context was written by another agent and may be stale, risk classifications on write operations, provenance footers that record who wrote what and when, file anchors with commit-at-write hashes for staleness detection, and read-time verification guidance. We present evidence that trust preambles reduced one class of context contamination from 88.8% to 33.3% in controlled testing, while being transparent about which attack classes remain unmitigated. The principle: stored context should be useful but never trusted by default.
Shub Argha
Head of Forward Deployed Engineering @ Arcade.dev
New York City, New York, United States
Links
Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.
Jump to top