MemPoison: Uncovering Persistent Memory Threats and Structural Blind Spots in LLM Agents
Jifeng Gao, Kang Xia, Yi Zhang, Xiaobin Hong, Mingkai Lin, Xingshen Wei, Wenzhong Li, Sanglu Lu
cs.CR, cs.AI
Submitted: 2026-07-16
License: http://arxiv.org/licenses/nonexclusive-distrib/1.0/
Terminology
Sources
- GPT-4 Technical Report
- Security in LLM-as-a-Judge: A Comprehensive SoK
- One Shot Dominance: Knowledge Poisoning Attack on Retrieval-Augmented Generation Systems
- Memory Injection Attacks on LLM Agents via Query-Only Interaction
- Memory for Autonomous LLM Agents:Mechanisms, Evaluation, and Emerging Frontiers
- BackdoorAgent: A Unified Framework for Backdoor Attacks on LLM-based Agents
- ChatGLM: A Family of Large Language Models from GLM-130B to GLM-4 All Tools
- The Llama 3 Herd of Models
- Evaluating Memory in LLM Agents via Incremental Multi-Turn Interactions
- Baseline Defenses for Adversarial Attacks Against Aligned Language Models
- Certifying LLM Safety against Adversarial Prompting
- A Survey on Long-Term Memory Security in LLM Agents: Attacks, Defenses, and Governance Across the Memory Lifecycle
- DeepSeek-V2: A Strong, Economical, and Efficient Mixture-of-Experts Language Model
- DeepSeek-V3 Technical Report
- Terminal-Bench: Benchmarking Agents on Hard, Realistic Tasks in Command Line Interfaces
- The Why Behind the Action: Unveiling Internal Drivers via Agentic Attribution
- SmoothLLM: Defending Large Language Models Against Jailbreaking Attacks
- Evaluating Memory Structure in LLM Agents
- OpenAI GPT-5 System Card
- MemoryGraft: Persistent Compromise of LLM Agents via Poisoned Experience Retrieval
Related papers
- SoK: AI-Augmented Binary Reversing
- Relaxed Sender Anonymity for CBDC Interbank Settlement: A Zero-Knowledge Approach on Permissioned EVM
- Calibration-Family Overfit: Why Trusted Sabotage Monitors Don't Transfer Across Lineages
- Efficient Fuzzy PSI under One-Sided Assumptions
- Sealing the Audit-Runtime Gap for LLM Skills
- Token Composition: A Graph Based on EVM Logs