August 2026Unreviewed
MAFIA: Query-Only Memory Attacks via Probing and Factual Injection against Audited LLM Agents
Jiaming Chen, Yisen Gao, Yanping Li, Zifan Liu, Yumeng Zhang, Jun Zhang
Abstract
Memory-augmented LLM agents rely on rich context for long-horizon reasoning and acting, yet their memory modules expose a persistent attack surface for malicious records, making the study of memory poisoning threats imperative. However, existing query-only attacks often fail to remain effective in two realistic and prevalent settings: large-scale benign memory pools and active input auditing. Consequently, current approaches fall short when facing the dual challenges of high retrieval competitiv
Categories
Framework mappings
OWASP Top 10 for LLM Applications
- LLM04Data and Model Poisoning
OWASP Top 10 for Agentic Applications
- ASI06Memory & Context Poisoning
MITRE ATLAS
- AML.T0020Poison Training Data
- AML.T0080AI Agent Context Poisoning
Suggested from the entry's categories.
Cite
@misc{chen2026mafia,
title = {{MAFIA: Query-Only Memory Attacks via Probing and Factual Injection against Audited LLM Agents}},
author = {Jiaming Chen and Yisen Gao and Yanping Li and Zifan Liu and Yumeng Zhang and Jun Zhang},
year = {2026},
month = aug,
eprint = {2608.03844},
archivePrefix = {arXiv},
url = {https://arxiv.org/abs/2608.03844}
}