Skip to content
Search
paperMay 2026Unreviewed

Hidden in Memory: Sleeper Memory Poisoning in LLM Agents

Sidharth Pulipaka, Stanislau Hlebik, Leonidas Raghav, Sahar Abdelnabi, Vyas Raina, Ivaxi Sheth, Mario Fritz

Abstract

Large language models are increasingly augmented with persistent memory, allowing assistants to store user-specific information across sessions for personalization and continuity. This statefulness introduces a new security risk: adversarial content can corrupt what an assistant remembers and thereby influence future interactions. We propose and study sleeper memory poisoning, a delayed attack in which an adversary manipulates external context, such as a document, webpage, or repository, to caus

Categories

Framework mappings

OWASP Top 10 for LLM Applications
  • LLM04Data and Model Poisoning
OWASP Top 10 for Agentic Applications
  • ASI06Memory & Context Poisoning
MITRE ATLAS
  • AML.T0020Poison Training Data
  • AML.T0080AI Agent Context Poisoning

Suggested from the entry's categories.

Cite

@misc{pulipaka2026hidden,
  title = {{Hidden in Memory: Sleeper Memory Poisoning in LLM Agents}},
  author = {Sidharth Pulipaka and Stanislau Hlebik and Leonidas Raghav and Sahar Abdelnabi and Vyas Raina and Ivaxi Sheth and Mario Fritz},
  year = {2026},
  month = may,
  eprint = {2605.15338},
  archivePrefix = {arXiv},
  url = {https://arxiv.org/abs/2605.15338}
}