When several AI agents share a memory cache, a harmless-looking number like churn_rate = 0.114 can be
derived from a column the requester may not read, here income. Role- and content-based checks pass, because a cached
scalar has no column to tag. This demo implements the Analytical Memory Unit (AMU) from the paper: every cached result
carries its derivation's sensitivity tag S(a) and definition hash H(a), and is served only if S(a) ⊆ P(requester).
Pick a requesting department and a metric. Try Marketing → churn_rate first, then Operations → avg_order_value_by_income_band.
Describe how a cached result was computed. The tag comes from every column the query read (joins, filters, aggregates), not only the columns it returned.
A seeded toy workload: four departments request metrics from one shared cache. On a miss the agent computes in its own scope and writes the result back. This illustrates the mechanism and is not the paper's experimental setup. The paper's measured results are in the table further down.
| Measure (as reported in the paper) | Result |
|---|---|
| Cross-department leakage, naive content-gated memory | 18.8% – 25.5% (synthetic / TPC-H) |
| Cross-department leakage, lineage-gated retrieval | 0% |
| Memory reuse retained under lineage gating | 81.5% – 82.6% |
| Worst-case gate overhead | 13.8 µs |
| Recorded lineage completeness needed to eliminate measured leakage | 75% – 90% (90% recommended deployment target) |
| Real-agent PoC (LLM-generated SQL) | 0 leaks over 9 round-trips; 2 definition conflicts caught |
Paper. Venkata Sangaraju, Sudhir Vissa. Lineage-Aware Memory Governance: A Derivation-Gated Framework for Privacy-Preserving Column-Level Access Control in Enterprise AI Agents. IEEE Access, 2026. arXiv:2610.07258 · DOI 10.1109/ACCESS.2026.3730363
The mechanism.
S(a) = (∪ columns touched by the derivation) ∩ sensitive-column registry H(a) = SHA256(sorted tables | sorted columns | filter)[:12] serve a cached entry only if S(a) ⊆ P(requester); scan newest-first; otherwise recompute in scope
Scope of the guarantee. Provided lineage recording is complete, the retrieval policy blocks any cached result derived from a sensitive column outside the requester's permissions. This is a conditional design guarantee, not an empirical claim. It does not cover derived features that encode sensitive information without naming their source column.
Everything on this page runs in your browser. No data leaves the page.
@article{sangaraju2026lineage,
title = {Lineage-Aware Memory Governance: A Derivation-Gated Framework for Privacy-Preserving Column-Level Access Control in Enterprise AI Agents},
author = {Sangaraju, Venkata and Vissa, Sudhir},
journal = {IEEE Access}, year = {2026},
doi = {10.1109/ACCESS.2026.3730363},
eprint = {2610.07258}, archivePrefix = {arXiv}
}