Skip to content
Search
paperAugust 2026Unreviewed

MAFIA: Query-Only Memory Attacks via Probing and Factual Injection against Audited LLM Agents

Jiaming Chen, Yisen Gao, Yanping Li, Zifan Liu, Yumeng Zhang, Jun Zhang

Abstract

Memory-augmented LLM agents rely on rich context for long-horizon reasoning and acting, yet their memory modules expose a persistent attack surface for malicious records, making the study of memory poisoning threats imperative. However, existing query-only attacks often fail to remain effective in two realistic and prevalent settings: large-scale benign memory pools and active input auditing. Consequently, current approaches fall short when facing the dual challenges of high retrieval competitiv

Categories

Framework mappings

OWASP Top 10 for LLM Applications
  • LLM04Data and Model Poisoning
OWASP Top 10 for Agentic Applications
  • ASI06Memory & Context Poisoning
MITRE ATLAS
  • AML.T0020Poison Training Data
  • AML.T0080AI Agent Context Poisoning

Suggested from the entry's categories.

Cite

@misc{chen2026mafia,
  title = {{MAFIA: Query-Only Memory Attacks via Probing and Factual Injection against Audited LLM Agents}},
  author = {Jiaming Chen and Yisen Gao and Yanping Li and Zifan Liu and Yumeng Zhang and Jun Zhang},
  year = {2026},
  month = aug,
  eprint = {2608.03844},
  archivePrefix = {arXiv},
  url = {https://arxiv.org/abs/2608.03844}
}