May 2026Unreviewed
Hidden in Memory: Sleeper Memory Poisoning in LLM Agents
Sidharth Pulipaka, Stanislau Hlebik, Leonidas Raghav, Sahar Abdelnabi, Vyas Raina, Ivaxi Sheth, Mario Fritz
Abstract
Large language models are increasingly augmented with persistent memory, allowing assistants to store user-specific information across sessions for personalization and continuity. This statefulness introduces a new security risk: adversarial content can corrupt what an assistant remembers and thereby influence future interactions. We propose and study sleeper memory poisoning, a delayed attack in which an adversary manipulates external context, such as a document, webpage, or repository, to caus
Categories
Framework mappings
OWASP Top 10 for LLM Applications
- LLM04Data and Model Poisoning
OWASP Top 10 for Agentic Applications
- ASI06Memory & Context Poisoning
MITRE ATLAS
- AML.T0020Poison Training Data
- AML.T0080AI Agent Context Poisoning
Suggested from the entry's categories.
Cite
@misc{pulipaka2026hidden,
title = {{Hidden in Memory: Sleeper Memory Poisoning in LLM Agents}},
author = {Sidharth Pulipaka and Stanislau Hlebik and Leonidas Raghav and Sahar Abdelnabi and Vyas Raina and Ivaxi Sheth and Mario Fritz},
year = {2026},
month = may,
eprint = {2605.15338},
archivePrefix = {arXiv},
url = {https://arxiv.org/abs/2605.15338}
}