Bad Memory: Evaluating Prompt Injection Risks from Memory in Agentic Systems
Soham Gadgil, David Alexander, Sai Sunku, Franziska Roesner
cs.CR, cs.AI, cs.MA
Submitted: 2026-07-16
Comments: Preprint
Code: https://github.com/multica-ai/andrej-karpathy-
License: http://arxiv.org/licenses/nonexclusive-distrib/1.0/
Terminology
Sources
- Evaluating Large Language Models Trained on Code
- Memory in the Age of AI Agents
- Prompt Injection attack against LLM-integrated Applications
- Large Language Model Agent: A Survey on Methodology, Applications and Challenges
- The Attacker Moves Second: Stronger Adaptive Attacks Bypass Defenses Against Llm Jailbreaks and Prompt Injections
- Ignore Previous Prompt: Attack Techniques For Language Models
- Under the Hood of SKILL.md: Semantic Supply-chain Attacks on AI Agent Skill Registry
- From Recall to Forgetting: Benchmarking Long-Term Memory for Personalized Agents
- Zombie Agents: Persistent Control of Self-Evolving LLM Agents via Self-Reinforcing Injections
- ReAct: Synergizing Reasoning and Acting in Language Models
Related papers
- SoK: AI-Augmented Binary Reversing
- Relaxed Sender Anonymity for CBDC Interbank Settlement: A Zero-Knowledge Approach on Permissioned EVM
- Calibration-Family Overfit: Why Trusted Sabotage Monitors Don't Transfer Across Lineages
- Efficient Fuzzy PSI under One-Sided Assumptions
- Sealing the Audit-Runtime Gap for LLM Skills
- Token Composition: A Graph Based on EVM Logs