Privacy-Preserving Federated Early Warning of Memory Poisoning for Consumer AI Agents
Document Type
Article
Source of Publication
IEEE Transactions on Consumer Electronics
Publication Date
1-1-2026
Abstract
Consumer AI agents increasingly rely on persistent long-term memory to support personalization, contextual continuity, and multi-step task execution, but this memory also creates a new attack surface in which memory poisoning can occur through malicious memory insertion, misleading memory updates, retrieval manipulation, or latent records that later induce reasoning errors. Existing studies have examined agent privacy leakage, retrieval corruption, and federated robustness, yet they rarely address the specific problem of forecasting whether a newly written memory record will trigger future reasoning deviation, measured as an observable divergence between the agent's later reasoning trace and a benign reference trajectory, under privacy-sensitive and heterogeneous deployment settings. To address this gap, this paper proposes FEMP-GUARD, a privacy-preserving federated early-warning framework for long-horizon memory poisoning in consumer AI agents. The proposed method models poisoning risk as a retrieval-conditioned temporal forecasting task, where each client locally encodes memory-writing events, retrieval dynamics, and behavioral context, and then participates in privacy-preserving personalized federated optimization without sharing raw memory traces. The predicted warning score is further coupled with local mitigation through write-time quarantine and retrieval-time reweighting. Experiments on four benchmarks, namely MIMIC-III, eICU, WebShop, and MMLU, show that FEMP-GUARD consistently outperforms representative federated baselines, achieving the best AUC, F1, Precision, Recall, and Early Warning Rate while also producing earlier warnings and favorable security-utility trade-offs. These results demonstrate that retrieval-conditioned federated early warning provides an effective and practical defense paradigm for protecting memory-augmented consumer AI agents against slow and stealthy poisoning behaviors.
DOI Link
ISSN
Publisher
Institute of Electrical and Electronics Engineers (IEEE)
Disciplines
Computer Sciences
Keywords
Consumer AI agents, federated learning, long-term memory security, memory poisoning, memory safety, privacy-preserving early warning
Scopus ID
Recommended Citation
Liu, Wei; Wang, Xuhan; Wang, Lihui; Dahmani, Nadia; and Pei, Jiaming, "Privacy-Preserving Federated Early Warning of Memory Poisoning for Consumer AI Agents" (2026). All Works. 8226.
https://zuscholars.zu.ac.ae/works/8226
Indexed in Scopus
yes
Open Access
no