Skip to content
Search
paperSeptember 2026Unreviewed

MemSentry: A Framework for Detecting Persistent Memory Poisoning in Agentic AI

Ayan Roy, Kaustuvi Basu

Abstract

Agentic AI systems with persistent memory introduce a distinct attack surface known as memory poisoning, in which adversarially crafted content is stored in long-term memory and subsequently influences future agent behavior. Such attacks can suppress security alerts, facilitate privilege escalation, alter trust relationships, or override security policies without modifying the underlying model weights or system prompts. To address this threat, we present MemSentry, a formal, configuration-driven

Categories

Framework mappings

OWASP Top 10 for LLM Applications
  • LLM04Data and Model Poisoning
OWASP Top 10 for Agentic Applications
  • ASI06Memory & Context Poisoning
MITRE ATLAS
  • AML.T0020Poison Training Data
  • AML.T0080AI Agent Context Poisoning

Suggested from the entry's categories.

Cite

@misc{roy2026memsentry,
  title = {{MemSentry: A Framework for Detecting Persistent Memory Poisoning in Agentic AI}},
  author = {Ayan Roy and Kaustuvi Basu},
  year = {2026},
  month = sep,
  eprint = {2609.08747},
  archivePrefix = {arXiv},
  url = {https://arxiv.org/abs/2609.08747}
}