Multi-user AI applications can leak information between users in subtle ways.
Leakage Paths
- Shared conversation context: bugs mixing sessions.
- Caching: cached responses or prompt prefixes containing user-specific data served to others.
- Memory features: long-term memories stored or retrieved under the wrong user.
- Shared retrieval indexes: documents from one tenant retrievable by another.
- Fine-tuning on user data: models learning and reproducing one user's information for others.
- Logs and analytics: user content visible to staff or tools without need.
Prevention
- Strict session and tenant isolation in code, with tests.
- Cache keys including user or tenant identifiers; don't cache sensitive responses in shared caches.
- Scope memory and retrieval by user and tenant.
- Avoid training shared models on user content without anonymisation and consent.
- Restrict access to logs.
Testing
Create multiple test users and tenants; attempt to access each other's data through direct and indirect questions.
Response
Treat cross-user leakage as a data breach: contain, investigate and notify as required.