{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,11]],"date-time":"2026-05-11T11:19:51Z","timestamp":1778498391668,"version":"3.51.4"},"publisher-location":"Singapore","reference-count":30,"publisher":"Springer Nature Singapore","isbn-type":[{"value":"9789819203741","type":"print"},{"value":"9789819203758","type":"electronic"}],"license":[{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2026]]},"DOI":"10.1007\/978-981-92-0375-8_36","type":"book-chapter","created":{"date-parts":[[2026,5,11]],"date-time":"2026-05-11T11:01:01Z","timestamp":1778497261000},"page":"596-612","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["Private Memory Under the\u00a0Spotlight: Diagnosing and\u00a0Defending User-Level Leakage in\u00a0LLM-Augmented Systems"],"prefix":"10.1007","author":[{"given":"Yinchi","family":"Ge","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Hui","family":"Zhang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Zhenyuan","family":"Huang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Haohang","family":"Sun","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Shenghao","family":"Jin","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Haijun","family":"Yang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2026,5,12]]},"reference":[{"key":"36_CR1","doi-asserted-by":"crossref","unstructured":"Abadi, M., et al.: Deep learning with differential privacy. In: Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security, pp. 308\u2013318 (2016)","DOI":"10.1145\/2976749.2978318"},{"key":"36_CR2","doi-asserted-by":"publisher","unstructured":"Cabrero-Daniel, B., Herda, T., Pichler, V., Eder, M.: Exploring human-AI collaboration in agile: customised LLM meeting assistants. In: \u0160mite, D., Guerra, E., Wang, X., Marchesi, M., Gregory, P. (eds.) XP 2024. LNBIP, vol. 512, pp. 163\u2013178. Springer, Cham (2024). https:\/\/doi.org\/10.1007\/978-3-031-61154-4_11","DOI":"10.1007\/978-3-031-61154-4_11"},{"key":"36_CR3","unstructured":"Carlini, N., Liu, C., Erlingsson, \u00da., Kos, J., Song, D.: The secret sharer: measuring unintended neural network memorization & extracting secrets. In: USENIX Security Symposium (2019)"},{"key":"36_CR4","unstructured":"Costa, M., et al.: Securing AI agents with information-flow control. arXiv preprint arXiv:2505.23643 (2025)"},{"key":"36_CR5","unstructured":"Debenedetti, E., et al.: Defeating prompt injections by design. arXiv preprint arXiv:2503.18813 (2025)"},{"issue":"1","key":"36_CR6","doi-asserted-by":"publisher","first-page":"3","DOI":"10.1111\/rssb.12454","volume":"84","author":"J Dong","year":"2022","unstructured":"Dong, J., Roth, A., Su, W.J.: Gaussian differential privacy. J. R. Stat. Soc. Ser. B Stat Methodol. 84(1), 3\u201337 (2022)","journal-title":"J. R. Stat. Soc. Ser. B Stat Methodol."},{"key":"36_CR7","doi-asserted-by":"crossref","unstructured":"Douze, M., et al.: The faiss library. IEEE Trans. Big Data (2025)","DOI":"10.1109\/TBDATA.2025.3618474"},{"key":"36_CR8","unstructured":"Durfee, D., Rogers, R.M.: Practical differentially private top-k selection with pay-what-you-get composition. In: Advances in Neural Information Processing Systems, vol. 32 (2019)"},{"key":"36_CR9","first-page":"1","volume-title":"Automata, Languages and Programming","author":"C Dwork","year":"2006","unstructured":"Dwork, C.: Differential privacy. In: Bugliesi, M., Preneel, B., Sassone, V., Wegener, I. (eds.) Automata, Languages and Programming, pp. 1\u201312. Springer, Heidelberg (2006)"},{"key":"36_CR10","doi-asserted-by":"crossref","unstructured":"Fredrikson, M., Jha, S., Ristenpart, T.: Model inversion attacks that exploit confidence information and basic countermeasures. In: Proceedings of the 22nd ACM SIGSAC Conference on Computer and Communications Security, pp. 1322\u20131333 (2015)","DOI":"10.1145\/2810103.2813677"},{"key":"36_CR11","unstructured":"Gemini Team et al.: Gemini: a family of highly capable multimodal models (2025). https:\/\/arxiv.org\/abs\/2312.11805"},{"key":"36_CR12","doi-asserted-by":"crossref","unstructured":"Hatalis, K., et al.: Memory matters: the need to improve long-term memory in LLM-agents. In: Proceedings of the AAAI Symposium Series, vol.\u00a02, pp. 277\u2013280 (2023)","DOI":"10.1609\/aaaiss.v2i1.27688"},{"key":"36_CR13","doi-asserted-by":"crossref","unstructured":"He, G., Demartini, G., Gadiraju, U.: Plan-then-execute: an empirical study of user trust and team performance when using LLM agents as a daily assistant. In: Proceedings of the 2025 CHI Conference on Human Factors in Computing Systems, pp. 1\u201322 (2025)","DOI":"10.1145\/3706598.3713218"},{"key":"36_CR14","doi-asserted-by":"crossref","unstructured":"Maharana, A., Lee, D.H., Tulyakov, S., Bansal, M., Barbieri, F., Fang, Y.: Evaluating very long-term conversational memory of LLM agents. In: Proceedings of the 62nd Annual Meeting of the Association for Computational Linguistics (Volume 1: Long Papers), pp. 13851\u201313870 (2024)","DOI":"10.18653\/v1\/2024.acl-long.747"},{"key":"36_CR15","unstructured":"Multi-Granularity, M.L.M.F.: M3-embedding: multi-linguality, multi-functionality, multi-granularity text embeddings through self-knowledge distillation (2024)"},{"key":"36_CR16","unstructured":"Nasr, M., et al.: The attacker moves second: Stronger adaptive attacks bypass defenses against LLM jailbreaks and prompt injections (2025). https:\/\/arxiv.org\/abs\/2510.09023"},{"key":"36_CR17","unstructured":"Notion: Use notion AI to give teams perfect memory and save time (2024). https:\/\/www.notion.com\/help\/guides\/use-notion-ai-to-give-teams-perfect-memory-and-save-time. Accessed 23 Oct 2025"},{"key":"36_CR18","unstructured":"OpenAI, Achiam, A., et al.: GPT-4 technical report (2024). https:\/\/arxiv.org\/abs\/2303.08774"},{"key":"36_CR19","doi-asserted-by":"crossref","unstructured":"Shokri, R., Stronati, M., Song, C., Shmatikov, V.: Membership inference attacks against machine learning models. In: 2017 IEEE Symposium on Security and Privacy (SP), pp. 3\u201318. IEEE (2017)","DOI":"10.1109\/SP.2017.41"},{"key":"36_CR20","unstructured":"Siddiqui, S.A., et al.: Permissive information-flow analysis for large language models. Transactions on Machine Learning Research (2025). https:\/\/openreview.net\/forum?id=ufYRO8y3mr"},{"key":"36_CR21","unstructured":"Slack: Slack AI has arrived (2024). https:\/\/slack.com\/intl\/zh-cn\/blog\/news\/slack-ai-has-arrived. Accessed 23 Oct 2025"},{"key":"36_CR22","unstructured":"Song, C., Shmatikov, V.: Overlearning reveals sensitive attributes. In: 8th International Conference on Learning Representations, ICLR 2020 (2020)"},{"key":"36_CR23","doi-asserted-by":"publisher","unstructured":"Wang, B., et al.: Unveiling privacy risks in LLM agent memory. In: Che, W., Nabende, J., Shutova, E., Pilehvar, M.T. (eds.) Proceedings of the 63rd Annual Meeting of the Association for Computational Linguistics (Volume 1: Long Papers), Vienna, Austria, pp. 25241\u201325260. Association for Computational Linguistics (2025). https:\/\/doi.org\/10.18653\/v1\/2025.acl-long.1227, https:\/\/aclanthology.org\/2025.acl-long.1227\/","DOI":"10.18653\/v1\/2025.acl-long.1227"},{"key":"36_CR24","first-page":"74530","volume":"36","author":"W Wang","year":"2023","unstructured":"Wang, W., et al.: Augmenting language models with long-term memory. Adv. Neural. Inf. Process. Syst. 36, 74530\u201374543 (2023)","journal-title":"Adv. Neural. Inf. Process. Syst."},{"key":"36_CR25","unstructured":"Wu, F., Cecchetti, E., Xiao, C.: System-level defense against indirect prompt injection attacks: An information flow control perspective. arXiv preprint arXiv:2409.19091 (2024)"},{"key":"36_CR26","unstructured":"Wu, T., Panda, A., Wang, J.T., Mittal, P.: Privacy-preserving in-context learning for large language models. In: The Twelfth International Conference on Learning Representations (2024)"},{"key":"36_CR27","doi-asserted-by":"crossref","unstructured":"Zeng, S., et\u00a0al.: The good and the bad: Exploring privacy issues in retrieval-augmented generation (rag). In: Findings of the Association for Computational Linguistics ACL 2024, pp. 4505\u20134524 (2024)","DOI":"10.18653\/v1\/2024.findings-acl.267"},{"issue":"6","key":"36_CR28","first-page":"1","volume":"43","author":"Z Zhang","year":"2025","unstructured":"Zhang, Z., et al.: A survey on the memory mechanism of large language model-based agents. ACM Trans. Inf. Syst. 43(6), 1\u201347 (2025)","journal-title":"ACM Trans. Inf. Syst."},{"key":"36_CR29","unstructured":"Zhong, P.Y., et al.: RTBas: defending LLM agents against prompt injection and privacy leakage. arXiv preprint arXiv:2502.08966 (2025)"},{"key":"36_CR30","doi-asserted-by":"crossref","unstructured":"Zhong, W., Guo, L., Gao, Q., Ye, H., Wang, Y.: Memorybank: enhancing large language models with long-term memory. In: Proceedings of the AAAI Conference on Artificial Intelligence, vol.\u00a038, pp. 19724\u201319731 (2024)","DOI":"10.1609\/aaai.v38i17.29946"}],"container-title":["Lecture Notes in Computer Science","Database Systems for Advanced Applications"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-981-92-0375-8_36","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,5,11]],"date-time":"2026-05-11T11:01:19Z","timestamp":1778497279000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-981-92-0375-8_36"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026]]},"ISBN":["9789819203741","9789819203758"],"references-count":30,"URL":"https:\/\/doi.org\/10.1007\/978-981-92-0375-8_36","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026]]},"assertion":[{"value":"12 May 2026","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"The authors have no competing interests to declare that are relevant to the content of this article.","order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Disclosure of Interests"}},{"value":"DASFAA","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Conference on Database Systems for Advanced Applications","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Jeju","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Korea (Republic of)","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2026","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"27 April 2026","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"30 April 2026","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"31","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"dasfaa2026","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/dasfaa2026.github.io\/index.html","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}