Skip to content
Search
paperMay 2026Unreviewed

Remembering More, Risking More: Longitudinal Safety Risks in Memory-Equipped LLM Agents

Ahmad Al-Tawaha, Shangding Gu, Peizhi Niu, Ruoxi Jia, Ming Jin

Abstract

Safety evaluations of memory-equipped LLM agents typically measure within-task safety: whether an agent completes a single scenario safely, often under adversarial conditions such as prompt injection or memory poisoning. In deployment, however, a single agent serves many independent tasks over a long horizon, and memory accumulated during earlier tasks can affect behavior on later, unrelated ones. Studying this regime requires evaluation along the temporal dimension across tasks: not whether an

Categories

Framework mappings

OWASP Top 10 for LLM Applications
  • LLM01Prompt Injection
  • LLM04Data and Model Poisoning
OWASP Top 10 for Agentic Applications
  • ASI06Memory & Context Poisoning
MITRE ATLAS
  • AML.T0020Poison Training Data
  • AML.T0051LLM Prompt Injection
  • AML.T0080AI Agent Context Poisoning

Suggested from the entry's categories.

Cite

@misc{altawaha2026remembering,
  title = {{Remembering More, Risking More: Longitudinal Safety Risks in Memory-Equipped LLM Agents}},
  author = {Ahmad Al-Tawaha and Shangding Gu and Peizhi Niu and Ruoxi Jia and Ming Jin},
  year = {2026},
  month = may,
  eprint = {2605.17830},
  archivePrefix = {arXiv},
  url = {https://arxiv.org/abs/2605.17830}
}