September 2026Unreviewed
CAPTURE: Disentangling Preference Drift from Memory Poisoning in Personalized LLM Agents
Asif Hossain, Ruksat Khan, Shayoni, Kishor Morol
Abstract
Personalized language agents use persistent memory to adapt to users over time, but the same mechanism creates an attack surface. When new information conflicts with stored preferences, an agent must distinguish genuine preference drift from temporary context shifts, ambiguity, or adversarial memory poisoning. We formulate this problem as a continuous-time partially observable decision process over a latent user state and show why rules based only on recency and provenance are insufficient. CAPT
Categories
Framework mappings
OWASP Top 10 for LLM Applications
- LLM04Data and Model Poisoning
OWASP Top 10 for Agentic Applications
- ASI06Memory & Context Poisoning
MITRE ATLAS
- AML.T0020Poison Training Data
- AML.T0080AI Agent Context Poisoning
Suggested from the entry's categories.
Cite
@misc{hossain2026capture,
title = {{CAPTURE: Disentangling Preference Drift from Memory Poisoning in Personalized LLM Agents}},
author = {Asif Hossain and Ruksat Khan and Shayoni and Kishor Morol},
year = {2026},
month = sep,
eprint = {2609.02265},
archivePrefix = {arXiv},
url = {https://www.semanticscholar.org/paper/6c2ef186b5091367d9c2667d2f3013a2b6f79ab7}
}