September 2026Unreviewed
MemSentry: A Framework for Detecting Persistent Memory Poisoning in Agentic AI
Ayan Roy, Kaustuvi Basu
Abstract
Agentic AI systems with persistent memory introduce a distinct attack surface known as memory poisoning, in which adversarially crafted content is stored in long-term memory and subsequently influences future agent behavior. Such attacks can suppress security alerts, facilitate privilege escalation, alter trust relationships, or override security policies without modifying the underlying model weights or system prompts. To address this threat, we present MemSentry, a formal, configuration-driven
Categories
Framework mappings
OWASP Top 10 for LLM Applications
- LLM04Data and Model Poisoning
OWASP Top 10 for Agentic Applications
- ASI06Memory & Context Poisoning
MITRE ATLAS
- AML.T0020Poison Training Data
- AML.T0080AI Agent Context Poisoning
Suggested from the entry's categories.
Cite
@misc{roy2026memsentry,
title = {{MemSentry: A Framework for Detecting Persistent Memory Poisoning in Agentic AI}},
author = {Ayan Roy and Kaustuvi Basu},
year = {2026},
month = sep,
eprint = {2609.08747},
archivePrefix = {arXiv},
url = {https://arxiv.org/abs/2609.08747}
}