Skip to content
Search
paperJune 2026Unreviewed

FragFuse: Bypassing Access Control of Large Language Model Agents via Memory-Based Query Fragmentation and Fusion

Zixin Rao, Wentian Zhu, Chan Aristella Lu, Zhaorun Chen, Wei Niu, Le Guan, Bo Li, Zhen Xiang

Abstract

Large language model (LLM) agents increasingly rely on long-term memory to support complex task execution, user personalization, and domain adaptation. Meanwhile, emerging access-control mechanisms for LLM agents are being explored to block policy-violating requests and prevent misuse. We reveal a novel attack surface arising from agent memory operations: prohibited content that would trigger access control can be fragmented across interactions, stored in long-term memory in benign-appearing for

Categories

Cite

@misc{rao2026fragfuse,
  title = {{FragFuse: Bypassing Access Control of Large Language Model Agents via Memory-Based Query Fragmentation and Fusion}},
  author = {Zixin Rao and Wentian Zhu and Chan Aristella Lu and Zhaorun Chen and Wei Niu and Le Guan and Bo Li and Zhen Xiang},
  year = {2026},
  month = jun,
  eprint = {2606.15609},
  archivePrefix = {arXiv},
  url = {https://arxiv.org/abs/2606.15609}
}