September 2026Unreviewed
Transferable End-to-End Optimization for Indirect Long-Term Memory Poisoning in LLM Agents
Chuanchao Zang, Jianing Wang, Wenyu Chen, Xiangtao Meng, Li Wang, Xinyu Gao, Zheng Li, Shanqing Guo
Abstract
Long-term memory can turn untrusted external content into persistent influence over an LLM agent's future decisions, creating the threat of indirect memory poisoning. A successful attack must survive a multi-stage pipeline comprising memory writing, retrieval, and utilization. Existing attacks largely rely on intra-stage optimization, optimizing individual stages in isolation while overlooking inter-stage coupling. Specifically, these stages impose different requirements on the same poisoning co
Categories
Framework mappings
OWASP Top 10 for LLM Applications
- LLM04Data and Model Poisoning
OWASP Top 10 for Agentic Applications
- ASI06Memory & Context Poisoning
MITRE ATLAS
- AML.T0020Poison Training Data
- AML.T0080AI Agent Context Poisoning
Suggested from the entry's categories.
Cite
@misc{zang2026transferable,
title = {{Transferable End-to-End Optimization for Indirect Long-Term Memory Poisoning in LLM Agents}},
author = {Chuanchao Zang and Jianing Wang and Wenyu Chen and Xiangtao Meng and Li Wang and Xinyu Gao and Zheng Li and Shanqing Guo},
year = {2026},
month = sep,
eprint = {2609.00523},
archivePrefix = {arXiv},
url = {https://arxiv.org/abs/2609.00523}
}