Correct Memory, Changed Assumptions: Procedural Transfer Across Trust Boundaries in Coding Agents
Anjum Asiya ⋅ Shashwat Suthar ⋅ Nayyar Zaidi
Abstract
A coding procedure can be correct in one setting but become unsafe when it is reused in a new setting where an important assumption has changed. We study this problem in coding agents that are given correct procedural memory from an earlier task and asked to solve a similar target task with a changed security-relevant assumption. We evaluate 13 synthetic task families across four memory conditions, two repetitions, and six completed model and agent configurations, producing 624 recorded runs and 595 technically valid outcomes. We measure functionality pass ($F$) and focal security witness pass ($S$) separately. The primary endpoint $U = F \land \neg S$ records functional completion with a focal witness failure. Compared with using no memory, correct source memory changes this failure rate by between $-11.5$ and $+13.6$ percentage points across configurations. The estimates include positive, zero, and negative values; every corresponding bootstrap interval includes zero. Lower $U$ can also accompany lower functionality. We also add a generic applicability reminder to correct source memory (B$-$C). Point estimates for $U$ are negative in all three Codex configurations, as are bounds for unresolved outcomes in the fixed recorded cohort; the MiniSWE configurations do not share that pattern. These observations concern complete configurations and do not establish model effects. In a 52-run analysis with the coding protocol and sampling rule frozen before annotation, two independent model-assisted coding passes agree on 22 implementations with target protection and seven traces with explicit assumption recognition before editing. Examination of matched transcripts and patches shows several behaviors, including reusing the source procedure without its target check, adapting it successfully, and reaching the same focal witness failure through different implementation paths. Overall, correct procedural memory is not automatically safe or unsafe when its original assumptions change. Evaluations of memory-assisted coding agents should therefore measure functional success and security properties separately, rather than treating successful task completion as sufficient evidence of safe transfer. Evaluations should measure functionality and the focal witness separately.
Chat is not available.
Successful Page Load