Privacy-Preserving Federated Early Warning of Memory Poisoning for Consumer AI Agents

Document Type

Article

Source of Publication

IEEE Transactions on Consumer Electronics

Publication Date

1-1-2026

Abstract

Consumer AI agents increasingly rely on persistent long-term memory to support personalization, contextual continuity, and multi-step task execution, but this memory also creates a new attack surface in which memory poisoning can occur through malicious memory insertion, misleading memory updates, retrieval manipulation, or latent records that later induce reasoning errors. Existing studies have examined agent privacy leakage, retrieval corruption, and federated robustness, yet they rarely address the specific problem of forecasting whether a newly written memory record will trigger future reasoning deviation, measured as an observable divergence between the agent's later reasoning trace and a benign reference trajectory, under privacy-sensitive and heterogeneous deployment settings. To address this gap, this paper proposes FEMP-GUARD, a privacy-preserving federated early-warning framework for long-horizon memory poisoning in consumer AI agents. The proposed method models poisoning risk as a retrieval-conditioned temporal forecasting task, where each client locally encodes memory-writing events, retrieval dynamics, and behavioral context, and then participates in privacy-preserving personalized federated optimization without sharing raw memory traces. The predicted warning score is further coupled with local mitigation through write-time quarantine and retrieval-time reweighting. Experiments on four benchmarks, namely MIMIC-III, eICU, WebShop, and MMLU, show that FEMP-GUARD consistently outperforms representative federated baselines, achieving the best AUC, F1, Precision, Recall, and Early Warning Rate while also producing earlier warnings and favorable security-utility trade-offs. These results demonstrate that retrieval-conditioned federated early warning provides an effective and practical defense paradigm for protecting memory-augmented consumer AI agents against slow and stealthy poisoning behaviors.

ISSN

0098-3063

Publisher

Institute of Electrical and Electronics Engineers (IEEE)

Disciplines

Computer Sciences

Keywords

Consumer AI agents, federated learning, long-term memory security, memory poisoning, memory safety, privacy-preserving early warning

Scopus ID

105045325973

Indexed in Scopus

yes

Open Access

no

Share

COinS