Presents kernel-managed shared memory that lets agents write tagged memories while the kernel enforces retrieval, privacy, and injection controls.

Topological visualization of Kernel-Managed Shared Memory for System-Wide Personalization
Brave API

Kernel-Managed Shared Memory is a system-level abstraction for multi-agent LLM systems where the agent-system kernel, rather than individual agents, governs memory retrieval, privacy enforcement, and prompt injection. Proposed by Ryan Lum and Yongfeng Zhang in a paper submitted to arXiv in September 2026, this design centralizes personalization logic to reduce duplication and improve consistency.

Core Mechanisms Centralized Control: Specialized agents (e.g., ProfileAgent, TaskAgent) write structured, tagged memories, while the kernel handles retrieval, visibility filtering, relevance ranking, and natural-language injection. Privacy Invariant: The system enforces a private-by-default visibility rule at the kernel level, ensuring that agents cannot exfiltrate private memories by omitting their own filtering logic; empirical tests showed 0/450 cross-agent exposures in private configurations. * Write-Ordering Barrier: To prevent race conditions where retrieval occurs before writes are indexed, the kernel uses a per-user monotonic sequence number and blocks retrieval until writes are drained, with a bounded timeout.

Performance and Evaluation Evaluated on the AIOS framework across three models (GPT-4o, Llama-3.1:8B, Qwen-2.5:7B) and 1,800 trials, the system demonstrated: Latency Reduction: End-to-end latency decreased by 15–61% compared to full unfiltered context concatenation, due to shorter prompts and reduced token usage. Quality Parity: It statistically matched the personalization quality of full-context concatenation on two of three models, while significantly outperforming standard retrieval-augmented injection (RAG) and unmanaged external memory backends (Mem0). * Limitations: The paper’s central claims rely heavily on an automated LLM judge (GPT-5.4), which critics note may inflate performance gaps; human evaluation consistency remains a point of contention.

Generated 1d ago
Open-Weights Reasoning

Kernel-Managed Shared Memory for System-Wide Personalization proposes an operating-system-level mechanism for persistent, shared personalization state used by AI agents. Rather than letting each agent maintain private, ad hoc memory stores, the paper describes a kernel-managed memory layer in which agents can write structured, tagged memories that are visible to other authorized components. The kernel is responsible for enforcing the policy layer: deciding which memories may be retrieved, how they may be scoped, what privacy constraints apply, and how they may be injected into agent context or prompts.

The key contribution is the shift from application-level memory management to a controlled, system-wide substrate. By placing retrieval, privacy, and injection controls in the kernel, the design aims to make personalization more consistent and safer across agents, processes, or services. Tagged memories allow fine-grained organization and policy evaluation, while kernel enforcement reduces reliance on each agent to self-police its context. This can help prevent common failure modes in agent systems, such as accidental leakage of sensitive personal data, uncontrolled propagation of stale or conflicting memories, and prompt-injection-like risks arising from unvetted context insertion.

The work matters because personalization is becoming a core capability of agentic systems, but it is also one of the least standardized and most security-sensitive parts of the stack. A kernel-managed approach offers a more principled architecture: personalization data becomes a governed system resource rather than an unmanaged side channel. If realized effectively, it could support auditable, privacy-preserving, and policy-compliant personalization across heterogeneous agents while giving system designers a single enforcement point for memory access and context injection.

Generated 1d ago
Sources