Proof-of-Execution Memory: Defending LLM Agents Against Forged-Reasoning Attacks by Verifying What Actually Happened
cs.CR
Submitted: 2026-08-17
Updated: 2026-08-29
Comments: 8 pages, 6 figures, 5 tables. Code: https://github.com/bithabib/ai_security
Code: https://github.com/bithabib/ai_security
License: http://arxiv.org/licenses/nonexclusive-distrib/1.0/
Terminology
Sources
- Memory Injection Attacks on LLM Agents via Query-Only Interaction
- AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases
- Context manipulation attacks : Web agents are susceptible to corrupted memory
- Real AI Agents with Fake Memories: Fatal Context Manipulation Attacks on Web3 Agents
- Your Agent's Memories Are Not Its Own: Forged Reasoning Attacks on LLM Agent Memory and Defenses
- Defeating Prompt Injections by Design
- Securing AI Agents with Information-Flow Control
- Progent: Securing AI Agents with Privilege Control
- RTBAS: Defending LLM Agents Against Prompt Injection and Privacy Leakage
- Formal Policy Enforcement for Real-World Agentic Systems
- AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents
- Adaptive Attacks Break Defenses Against Indirect Prompt Injection Attacks on LLM Agents
- The Attacker Moves Second: Stronger Adaptive Attacks Bypass Defenses Against Llm Jailbreaks and Prompt Injections
- A-MemGuard: A Proactive Defense Framework for LLM-Based Agent Memory
- MemAudit: Post-hoc Auditing of Poisoned Agent Memory via Causal Attribution and Structural Anomaly Detection
- MEMSAD: Gradient-Coupled Anomaly Detection for Memory Poisoning in Retrieval-Augmented Agents
- SMSR: Certified Defence Against Runtime Memory Poisoning in Persistent LLM Agent Systems
- A Survey on Long-Term Memory Security in LLM Agents: Attacks, Defenses, and Governance Across the Memory Lifecycle
- Reasoning-Style Poisoning of LLM Agents via Stealthy Style Transfer: Process-Level Attacks and Runtime Monitoring in RSV Space
Related papers
- SoK: AI-Augmented Binary Reversing
- Relaxed Sender Anonymity for CBDC Interbank Settlement: A Zero-Knowledge Approach on Permissioned EVM
- Calibration-Family Overfit: Why Trusted Sabotage Monitors Don't Transfer Across Lineages
- Efficient Fuzzy PSI under One-Sided Assumptions
- Sealing the Audit-Runtime Gap for LLM Skills
- Token Composition: A Graph Based on EVM Logs