MemRiskBench: Trace-Aware Risk-Preserving Evaluation for Long-Horizon LLM Agents

📅 2026-09-13
📈 Citations: 0
Influential: 0
📄 PDF
🤖 AI Summary
为解决长周期LLM代理中的记忆风险问题,本文提出了MemRiskBench,通过五类风险分类及基于确定性追踪的检查方法进行评估。
📝 Abstract
Long-horizon LLM agents accumulate memory across sessions, creating sparse but high-impact risks: stale facts, conflicting updates, cross-user leakage, revoked-memory reuse, and constraint decay. Standard aggregate scores hide per-risk failure rates--a model achieving 78% average accuracy may still leak data in 4% of episodes--and benchmark compression preferentially discards the rare high-severity events that distinguish a mostly-working model from one that occasionally causes harm. We present MemRiskBench. The primary contribution is a five-category risk taxonomy (plus one documented, unscored category) operationalized by deterministic trace grounded checks, instantiated as a 120-episode scripted benchmark with full trace logging and no LLM-as-judge on the pass/fail path, evaluated on five locally run quantized instruction-tuned models. Second, a risk-preserving subset selector: a coverage-constrained greedy selector on deterministic trace-derived features that retains full ranking (Spearman rho = 0.975, deterministic; CI collapses to a point estimate with zero bootstrap variance), risk coverage (1.0), and high-risk model detection (1.0) at a 20% subset size, reducing compute 5x. Unlike ranking-only subset selectors, this selector additionally preserves risk-type coverage and high-risk detection using trace-grounded deterministic features that do not require an LLM judge. All episodes, traces, the scoring implementation, and the selector are released to support reproducible evaluation and risk assessment of deployed LLM agents
Problem

Research questions and friction points this paper is trying to address.

Long-horizon LLM agents
memory accumulation
high-impact risks
Innovation

Methods, ideas, or system contributions that make the work stand out.

MemRiskBench
risk-preserving
trace-aware
deterministic trace checks
coverage-constrained greedy selector
🔎 Similar Papers
No similar papers found.
💼 Related Jobs
No related jobs found.
J
Jianhua Jiang
School of Artificial Intelligence and Computer Science, Jilin University of Finance and Economics, 130117 Changchun, China; Jilin Province Key Laboratory of Fintech, Jilin University of Finance and Economics, 130117 Changchun, China
D
Dongbo Yuan
School of Artificial Intelligence and Computer Science, Jilin University of Finance and Economics, 130117 Changchun, China
Weihua Li
Weihua Li
Senior Lecturer, Auckland University of Technology
multi-agent systemssocial networksocial influenceknoweldge graphnatural language processing