July 2026Unreviewed
Bad Memory: Evaluating Prompt Injection Risks from Memory in Agentic Systems
Soham Gadgil, David Alexander, Sai Sunku, Franziska Roesner
Abstract
A growing class of agentic systems maintain persistent state across sessions through memory files, behavioral preferences, and knowledge bases. While this makes agents more useful and self-improving, it also creates a new attack surface for prompt injections in which malicious instructions can be embedded within persistent files and influence future behavior. In this work, we study prompt injection attacks in memory-based agentic systems using a sandboxed synthetic workspace. We evaluate two age
Categories
Framework mappings
OWASP Top 10 for LLM Applications
- LLM01Prompt Injection
MITRE ATLAS
- AML.T0051LLM Prompt Injection
Suggested from the entry's categories.
Cite
@misc{gadgil2026bad,
title = {{Bad Memory: Evaluating Prompt Injection Risks from Memory in Agentic Systems}},
author = {Soham Gadgil and David Alexander and Sai Sunku and Franziska Roesner},
year = {2026},
month = jul,
eprint = {2607.14611},
archivePrefix = {arXiv},
url = {https://arxiv.org/abs/2607.14611}
}