// HACKER NEWS — CYBERSECURITY
I accidentally turned LLM memory into program analysis
Over the past few months I have been playing around quite a bit with LLM agents, particularly for vulnerability research.
They are becoming surprisingly good at navigating large codebases, explaining unfamiliar subsystems and helping explore potential attack surfaces. However, once an investigation starts taking a few hours, I kept running into the same problem: the model would slowly lose track of what we had actually established.
It might suggest an approach that we had already ruled out, forget that an assumption turned out to be false, or confidently continue reasoning from an observation that was no longer valid. Obviously, telling an LLM that something is wrong does not necessarily mean that it will stop believing all of the things that depended on it :)
I initially started looking into memory systems because I wanted to make LLMs more useful for complex vulnerability research and reduce this type of hallucination.
There are of course already plenty of solutions for giving LLMs memory. Usually this involves storing old conversations or observations somewhere, embedding them, and then retrieving the most relevant pieces whenever the model needs them again.
This works reasonably well, but there was something about it that bothered me.
During a vulnerability research sesh, I don’t just want the model to remember what we said.
Imagine that during an investigation we establish the following:
From this, we may conclude that the attacker can control a kernel object.
A normal memory system could store all of these observations and retrieve them again whenever we ask about the exploitability of the bug. The LLM then figures out the same conclusion.