EvidenceDemonstrated research proof-of-conceptv1.22.1

In plain English

This page shows what kind of support exists for each claim: real systems, experiments, early evidence, architectural reasoning, open questions, or speculative scenarios.

  • Why this matters: AI risk can come from the whole arrangement, not one obvious model.
  • What to look for: data, memory, routes, adapters, tools, evaluators, updates, and rollback paths.
  • Technical version below: the expert terminology remains available and is linked through the glossary.

Hijacking Agent Memory: Stealthy Trojan Attacks Through Conversational Interaction

Evidence card

Claim
Selective memory extraction and rewriting can create non-obvious persistence paths.
Evidence level
Emerging evidence
Source
https://arxiv.org/abs/2605.29960
Publication date
2026-05-28
Authors or institution
Hongtao Wang, Se Yang, Yu Chen, Puzhuo Liu
System tested
Long-term memory pipelines in LLM agents under reported conversational poisoning settings.
Limitations
Very recent preprint; operational systems may use different memory pipelines and mitigations.
What the evidence does show
Selective memory extraction and rewriting can create non-obvious persistence paths.
What the evidence does not show
That persistent memory should never be used.
Date last reviewed in UTC
2026-06-26T00:00:00Z

Site use

This source supports Cognivirus.com pages related to memory poisoning, selective memory, conversational attack surface. Its role is bounded by the limitations listed above.