August 2026Unreviewed
Salami Attack: Stealthy Collusive Memory Poisoning against OpenClaw
Zheng Lin, Yuzhen Huang, Zhenxing Niu, Xianmin Ye, Haichang Gao
Abstract
Long-term memory enables LLM agents to retain useful information across sessions, but also creates an attack surface through which adversaries may poison an agent's persistent memory to steer its behavior. Existing memory poisoning attacks mainly rely on individually malicious records, overlooking a compositional threat: multiple benign-looking memories may jointly induce unsafe behavior. In this paper, we introduce MemCollusion, an automated red-teaming framework for constructing collusive memo
Categories
Framework mappings
OWASP Top 10 for LLM Applications
- LLM04Data and Model Poisoning
OWASP Top 10 for Agentic Applications
- ASI06Memory & Context Poisoning
MITRE ATLAS
- AML.T0020Poison Training Data
- AML.T0080AI Agent Context Poisoning
NIST AI Risk Management Framework
- MEASUREMeasure
Suggested from the entry's categories.
Cite
@misc{lin2026salami,
title = {{Salami Attack: Stealthy Collusive Memory Poisoning against OpenClaw}},
author = {Zheng Lin and Yuzhen Huang and Zhenxing Niu and Xianmin Ye and Haichang Gao},
year = {2026},
month = aug,
eprint = {2608.01637},
archivePrefix = {arXiv},
url = {https://www.semanticscholar.org/paper/78a6fa7c6a59bb5fe8b4337b6f1b3d9b7b69328b}
}