BMA: Backchain Memory Attacks Create Unauthorized Control Paths in LLM Agents
cs.CR
Submitted: 2026-09-26
Updated: 2026-09-26
Terminology
Sources
- GEPA: Reflective Prompt Evolution Can Outperform Reinforcement Learning
- Mem0: Building Production-Ready AI Agents with Scalable Long-Term Memory
- Trojan Hippo Bench: A Dynamic Benchmark for Persistent Memory Attacks and Defenses in LLM Agents
- From Untrusted Input to Trusted Memory: A Systematic Study of Memory Poisoning Attacks in LLM Agents
- Memory Injection Attacks on LLM Agents via Query-Only Interaction
- The Llama 3 Herd of Models
- Not what you've signed up for: Compromising Real-World LLM-Integrated Applications with Indirect Prompt Injection
- MemoryArena: Benchmarking Agent Memory in Interdependent Multi-Session Agentic Tasks
- Securing LLM-Agent Long-Term Memory Against Poisoning: Non-Malleable, Origin-Bound Authority with Machine-Checked Guarantees
- MemLineage: Lineage-Guided Enforcement for LLM Agent Memory
- MemGPT: Towards LLMs as Operating Systems
- ER-MIA: Black-Box Adversarial Memory Injection Attacks on Long-Term Memory-Augmented Large Language Models
- Hidden in Memory: Sleeper Memory Poisoning in LLM Agents
- GateMem: Benchmarking Memory Governance in Multi-Principal Shared-Memory Agents
- Mem2ActBench: A Benchmark for Evaluating Long-Term Memory Utilization in Task-Oriented Autonomous Agents
- MemoryGraft: Persistent Compromise of LLM Agents via Poisoned Experience Retrieval
- MemAudit: Post-hoc Auditing of Poisoned Agent Memory via Causal Attribution and Structural Anomaly Detection
- ToolAlpaca: Generalized Tool Learning for Language Models with 3000 Simulated Cases
- Active Context Compression: Autonomous Memory Management in LLM Agents
- MemPoison: Bypassing Selective Memory Mechanisms to Plant Backdoors in LLM Agents
Related papers
- SoK: AI-Augmented Binary Reversing
- Relaxed Sender Anonymity for CBDC Interbank Settlement: A Zero-Knowledge Approach on Permissioned EVM
- Calibration-Family Overfit: Why Trusted Sabotage Monitors Don't Transfer Across Lineages
- Efficient Fuzzy PSI under One-Sided Assumptions
- Sealing the Audit-Runtime Gap for LLM Skills
- Token Composition: A Graph Based on EVM Logs