Skip to content
Search
paperSeptember 2026Unreviewed

Transferable End-to-End Optimization for Indirect Long-Term Memory Poisoning in LLM Agents

Chuanchao Zang, Jianing Wang, Wenyu Chen, Xiangtao Meng, Li Wang, Xinyu Gao, Zheng Li, Shanqing Guo

Abstract

Long-term memory can turn untrusted external content into persistent influence over an LLM agent's future decisions, creating the threat of indirect memory poisoning. A successful attack must survive a multi-stage pipeline comprising memory writing, retrieval, and utilization. Existing attacks largely rely on intra-stage optimization, optimizing individual stages in isolation while overlooking inter-stage coupling. Specifically, these stages impose different requirements on the same poisoning co

Categories

Framework mappings

OWASP Top 10 for LLM Applications
  • LLM04Data and Model Poisoning
OWASP Top 10 for Agentic Applications
  • ASI06Memory & Context Poisoning
MITRE ATLAS
  • AML.T0020Poison Training Data
  • AML.T0080AI Agent Context Poisoning

Suggested from the entry's categories.

Cite

@misc{zang2026transferable,
  title = {{Transferable End-to-End Optimization for Indirect Long-Term Memory Poisoning in LLM Agents}},
  author = {Chuanchao Zang and Jianing Wang and Wenyu Chen and Xiangtao Meng and Li Wang and Xinyu Gao and Zheng Li and Shanqing Guo},
  year = {2026},
  month = sep,
  eprint = {2609.00523},
  archivePrefix = {arXiv},
  url = {https://arxiv.org/abs/2609.00523}
}