Do Agents Dream of False Memories? Black-box Visual Attacks on Long-term Memory in Multimodal AI Agents
Halima Bouzidi, Mboutidem Ekemini Mkpong, Mohammad Abdullah Al Faruque
cs.CR, cs.CV, cs.LG
Submitted: 2026-07-17
Comments: 34 pages, 5 figures, 15 tables
License: http://arxiv.org/licenses/nonexclusive-distrib/1.0/
Terminology
Sources
- Conversational Health Agents: A Personalized LLM-Powered Agent Framework
- GPT-4 Technical Report
- Abusing Images and Sounds for Indirect Instruction Injection in Multi-Modal LLMs
- Mem-Gallery: Benchmarking Multimodal Long-Term Conversational Memory for MLLM Agents
- Poisoning Attacks against Support Vector Machines
- TeleMem: Building Long-Term and Multimodal Memory for Agentic AI
- Targeted Backdoor Attacks on Deep Learning Systems Using Data Poisoning
- Secure Retrieval-Augmented Generation against Poisoning Attacks
- Mem0: Building Production-Ready AI Agents with Scalable Long-Term Memory
- Gemini 2.5: Pushing the Frontier with Advanced Reasoning, Multimodality, Long Context, and Next Generation Agentic Capabilities
- Memory Injection Attacks on LLM Agents via Query-Only Interaction
- AssistGPT: A General Multi-modal Assistant that can Plan, Execute, Inspect, and Learn
- Retrieval-Augmented Generation for Large Language Models: A Survey
- Explaining and Harnessing Adversarial Examples
- BadNets: Identifying Vulnerabilities in the Machine Learning Model Supply Chain
- MM-PoisonRAG: Disrupting Multimodal RAG with Local and Global Poisoning Attacks
- Google's Cloud Vision API Is Not Robust To Noise
- Pre-Storage Reasoning for Episodic Memory: Shifting Inference Burden to Memory for Personalized Dialogue
- MemVerse: Multimodal Memory for Lifelong Learning Agents
- Seeing, Listening, Remembering, and Reasoning: A Multimodal Agent with Long-Term Memory
Related papers
- SoK: AI-Augmented Binary Reversing
- Relaxed Sender Anonymity for CBDC Interbank Settlement: A Zero-Knowledge Approach on Permissioned EVM
- Calibration-Family Overfit: Why Trusted Sabotage Monitors Don't Transfer Across Lineages
- Efficient Fuzzy PSI under One-Sided Assumptions
- Sealing the Audit-Runtime Gap for LLM Skills
- Token Composition: A Graph Based on EVM Logs