Skip to content
Search
paperMarch 2026Unreviewed

Memory poisoning and secure multi-agent systems

Vicenç Torra, Maria Bras-Amorós

Abstract

Memory poisoning attacks for Agentic AI and multi-agent systems (MAS) have recently caught attention. It is partially due to the fact that Large Language Models (LLMs) facilitate the construction and deployment of agents. Different memory systems are being used nowadays in this context, including semantic, episodic, and short-term memory. This distinction between the different types of memory systems focuses mostly on their duration but also on their origin and their localization. It ranges from

Categories

Framework mappings

OWASP Top 10 for LLM Applications
  • LLM04Data and Model Poisoning
OWASP Top 10 for Agentic Applications
  • ASI06Memory & Context Poisoning
MITRE ATLAS
  • AML.T0020Poison Training Data
  • AML.T0080AI Agent Context Poisoning

Suggested from the entry's categories.

Cite

@misc{torra2026memory,
  title = {{Memory poisoning and secure multi-agent systems}},
  author = {Vicenç Torra and Maria Bras-Amorós},
  year = {2026},
  month = mar,
  eprint = {2603.20357},
  archivePrefix = {arXiv},
  url = {https://arxiv.org/abs/2603.20357}
}