Skip to content
Search
paperSeptember 2026Unreviewed

CAPTURE: Disentangling Preference Drift from Memory Poisoning in Personalized LLM Agents

Asif Hossain, Ruksat Khan, Shayoni, Kishor Morol

Abstract

Personalized language agents use persistent memory to adapt to users over time, but the same mechanism creates an attack surface. When new information conflicts with stored preferences, an agent must distinguish genuine preference drift from temporary context shifts, ambiguity, or adversarial memory poisoning. We formulate this problem as a continuous-time partially observable decision process over a latent user state and show why rules based only on recency and provenance are insufficient. CAPT

Categories

Framework mappings

OWASP Top 10 for LLM Applications
  • LLM04Data and Model Poisoning
OWASP Top 10 for Agentic Applications
  • ASI06Memory & Context Poisoning
MITRE ATLAS
  • AML.T0020Poison Training Data
  • AML.T0080AI Agent Context Poisoning

Suggested from the entry's categories.

Cite

@misc{hossain2026capture,
  title = {{CAPTURE: Disentangling Preference Drift from Memory Poisoning in Personalized LLM Agents}},
  author = {Asif Hossain and Ruksat Khan and Shayoni and Kishor Morol},
  year = {2026},
  month = sep,
  eprint = {2609.02265},
  archivePrefix = {arXiv},
  url = {https://www.semanticscholar.org/paper/6c2ef186b5091367d9c2667d2f3013a2b6f79ab7}
}