EvidenceDemonstrated research proof-of-conceptv1.22.1
In plain English
This page shows what kind of support exists for each claim: real systems, experiments, early evidence, architectural reasoning, open questions, or speculative scenarios.
- Why this matters: AI risk can come from the whole arrangement, not one obvious model.
- What to look for: data, memory, routes, adapters, tools, evaluators, updates, and rollback paths.
- Technical version below: the expert terminology remains available and is linked through the glossary.
Hijacking Agent Memory: Stealthy Trojan Attacks Through Conversational Interaction
Evidence card
- Claim
- Selective memory extraction and rewriting can create non-obvious persistence paths.
- Evidence level
- Emerging evidence
- Source
- https://arxiv.org/abs/2605.29960
- Publication date
- 2026-05-28
- Authors or institution
- Hongtao Wang, Se Yang, Yu Chen, Puzhuo Liu
- System tested
- Long-term memory pipelines in LLM agents under reported conversational poisoning settings.
- Limitations
- Very recent preprint; operational systems may use different memory pipelines and mitigations.
- What the evidence does show
- Selective memory extraction and rewriting can create non-obvious persistence paths.
- What the evidence does not show
- That persistent memory should never be used.
- Date last reviewed in UTC
- 2026-06-26T00:00:00Z
Site use
This source supports Cognivirus.com pages related to memory poisoning, selective memory, conversational attack surface. Its role is bounded by the limitations listed above.