A Survey on Long-Term Memory Security in LLM Agents: Attacks, Defenses, and Governance Across the Memory Lifecycle
cs.CR, cs.AI, cs.CL
Submitted: 2026-04-17
Updated: 2026-09-22
Terminology
Sources
- Phantom: General Backdoor Attacks on Retrieval Augmented Language Generation
- KEPo: Knowledge Evolution Poison on Graph-based Retrieval-Augmented Generation
- AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases
- Mem0: Building Production-Ready AI Agents with Scalable Long-Term Memory
- Here Comes The AI Worm: Unleashing Zero-click Worms that Target GenAI-Powered Applications
- Securing AI Agents with Information-Flow Control
- Defeating Prompt Injections by Design
- AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents
- Memory Injection Attacks on LLM Agents via Query-Only Interaction
- From Local to Global: A Graph RAG Approach to Query-Focused Summarization
- AgentLeak: A Benchmark for Internal-Channel Privacy Leakage in Multi-Agent LLM Systems
- When Personalization Legitimizes Risks: Uncovering Safety Vulnerabilities in Personalized Dialogue Agents
- The Emerged Security and Privacy of LLM Agent: A Survey with Case Studies
- External Data Extraction Attacks against Retrieval-Augmented Large Language Models
- Evaluating Memory in LLM Agents via Incremental Multi-Turn Interactions
- Memory in the Age of AI Agents
- Preventing Prompt Injection with Type-Directed Privilege Separation
- A Vision for Access Control in LLM-based Agent Systems
- MemOS: A Memory OS for AI System
- GraphRAG under Fire
Related papers
- SoK: AI-Augmented Binary Reversing
- Relaxed Sender Anonymity for CBDC Interbank Settlement: A Zero-Knowledge Approach on Permissioned EVM
- Calibration-Family Overfit: Why Trusted Sabotage Monitors Don't Transfer Across Lineages
- Efficient Fuzzy PSI under One-Sided Assumptions
- Sealing the Audit-Runtime Gap for LLM Skills
- Token Composition: A Graph Based on EVM Logs