登録して招待リンクを共有すると、動画再生報酬と紹介報酬を獲得できます。

cv usk
@cv_usk
AI / Software Research Notes AI Agent, LLMOps, MLOps, Software Architecture 投稿は個人の意見です。
参加 May 2026
280 フォロー中    413 ファン
# Practices for Embedding AI Agents in Software # Memory Write Gate / Quarantine 🎯 The Hook The LLM guessed a user's preference, stored it as fact, and every future session now builds on that wrong assumption. Memory contamination accumulates silently with no error in the logs. 🔥 The Problem Writing to long-term memory is a near-irreversible operation. Without a write gate, three problems cascade. Hallucinated information gets persisted and self-reinforces as the agent later treats its own guesses as established facts. Malicious instructions embedded in external inputs get written to memory, creating persistent injection that outlasts a single session. And the same fact stored in slightly different forms produces contradictory search results that degrade response quality. Memory contamination is especially dangerous because it leaves no error trace. 💡 The Pattern Gate all writes to long-term memory through trust scoring, duplicate detection, PII/sensitivity filtering, and source verification. Facts explicitly stated by the user get auto-written. Inferred or unverified information goes to a quarantine zone pending human or supervisor approval. Deduplicate using cosine similarity at a 0.90-0.95 threshold, overwriting when the same entity and attribute are detected. Raise trust thresholds as input trust decreases and failure cost increases. ✅ When to Use Use when: - The agent has persistent long-term memory that survives across sessions - Memory candidates come from free-form user input or external documents - Wrong memories could affect downstream decisions in finance, healthcare, or legal domains Don't use when: - Memory is a session-scoped scratchpad that gets discarded at session end - Memory is fully admin-managed and the agent has read-only access ⚠️ Pitfalls - Quarantine zones bloat if the approval flow stalls. Set a TTL of 7-30 days and auto-discard unapproved entries - Embedding similarity alone can't distinguish "different attribute of the same person" from "updated value of the same attribute." Use structured metadata alongside vectors - If any code path writes directly to the memory store bypassing the gate, the entire pattern is rendered useless 🔧 Implementation Approach - Structure the write gate as a three-stage pipeline: duplicate detection, trust scoring, and PII/sensitivity filtering, routing all writes through this single path - Score trust based on the combination of source (user-explicit/agent-inferred/external) and grounding (cited/uncited), quarantining entries below the threshold - Combine cosine similarity with structured metadata (entity ID + attribute key) for deduplication, accurately distinguishing updates from new entries - Set a TTL on the quarantine zone to auto-discard unapproved entries, and enforce an architectural constraint that prohibits direct write APIs to the memory store #AIAgents# #SoftwareArchitecture#
もっと見る