EvidenceDemonstrated research proof-of-conceptv1.22.1
In plain English
This page shows what kind of support exists for each claim: real systems, experiments, early evidence, architectural reasoning, open questions, or speculative scenarios.
- Why this matters: AI risk can come from the whole arrangement, not one obvious model.
- What to look for: data, memory, routes, adapters, tools, evaluators, updates, and rollback paths.
- Technical version below: the expert terminology remains available and is linked through the glossary.
From Untrusted Input to Trusted Memory: A Systematic Study of Memory Poisoning Attacks in LLM Agents
Evidence card
- Claim
- Persistent memory can turn untrusted interaction into long-lived influence over future behavior.
- Evidence level
- Emerging evidence
- Source
- https://arxiv.org/abs/2606.04329
- Publication date
- 2026-06-03
- Authors or institution
- Pritam Dash, Tongyu Ge, Aditi Jain, Tanmay Shah, Zhiwei Shang
- System tested
- LLM-based agents with memory-write channels and MPBench as reported.
- Limitations
- Very recent preprint; benchmark representativeness and defenses need review.
- What the evidence does show
- Persistent memory can turn untrusted interaction into long-lived influence over future behavior.
- What the evidence does not show
- That all memory systems are equally vulnerable or that cleanup is impossible.
- Date last reviewed in UTC
- 2026-06-26T00:00:00Z
Site use
This source supports Cognivirus.com pages related to memory poisoning, persistent memory, agent security. Its role is bounded by the limitations listed above.