July 2026Unreviewed
When Agents Remember Too Much: Memory Poisoning Attacks on Large Language Model Agents
George Torres, Sharad Shrestha, Satyajayant Misra
Abstract
Personal AI agents powered by large language models can reason and act using available tools to access emails, manage calendars, and push code to remote repositories, all with minimal oversight. When augmented with long-term memory, an agent can recall specific details relevant to the current task, reducing the need for large context windows. Currently, long-term memory agents tend to fall into two distinct domains: conversational and action-planning agents. Personal assistant agents sit at the
Categories
Framework mappings
OWASP Top 10 for LLM Applications
- LLM04Data and Model Poisoning
OWASP Top 10 for Agentic Applications
- ASI06Memory & Context Poisoning
MITRE ATLAS
- AML.T0020Poison Training Data
- AML.T0080AI Agent Context Poisoning
Suggested from the entry's categories.
Cite
@misc{torres2026when,
title = {{When Agents Remember Too Much: Memory Poisoning Attacks on Large Language Model Agents}},
author = {George Torres and Sharad Shrestha and Satyajayant Misra},
year = {2026},
month = jul,
eprint = {2607.06595},
archivePrefix = {arXiv},
url = {https://arxiv.org/abs/2607.06595}
}