Skip to content
Search
paperJuly 2026Unreviewed

When Agents Remember Too Much: Memory Poisoning Attacks on Large Language Model Agents

George Torres, Sharad Shrestha, Satyajayant Misra

Abstract

Personal AI agents powered by large language models can reason and act using available tools to access emails, manage calendars, and push code to remote repositories, all with minimal oversight. When augmented with long-term memory, an agent can recall specific details relevant to the current task, reducing the need for large context windows. Currently, long-term memory agents tend to fall into two distinct domains: conversational and action-planning agents. Personal assistant agents sit at the

Categories

Framework mappings

OWASP Top 10 for LLM Applications
  • LLM04Data and Model Poisoning
OWASP Top 10 for Agentic Applications
  • ASI06Memory & Context Poisoning
MITRE ATLAS
  • AML.T0020Poison Training Data
  • AML.T0080AI Agent Context Poisoning

Suggested from the entry's categories.

Cite

@misc{torres2026when,
  title = {{When Agents Remember Too Much: Memory Poisoning Attacks on Large Language Model Agents}},
  author = {George Torres and Sharad Shrestha and Satyajayant Misra},
  year = {2026},
  month = jul,
  eprint = {2607.06595},
  archivePrefix = {arXiv},
  url = {https://arxiv.org/abs/2607.06595}
}