Skip to content
Search
paperAugust 2026Unreviewed

MAPLE-Guard: Memory-Aware Link Enforcement Against Memory-Link Poisoning in Multi-Agent Systems

Wen-Jun Xiong, Yi-Jin Zhou, Jia-Qian Wang, Shangding Gu, Bo Tang, Zhiyu Li, Feiyu Xiong, Ying Wen, Muning Wen

Abstract

LLM-based multi-agent systems (MAS) increasingly rely on persistent private and shared memories for long-horizon coordination. This memory layer improves continuity, but it also gives attackers a durable channel: a poisoned memory can be written once, continuously retrieved in later tasks, promoted into shared memory, and reused by other agents. A single poisoned write can therefore steer many later decisions and contaminate agents that never saw the original attack, all while no malicious messa

Categories

Framework mappings

OWASP Top 10 for LLM Applications
  • LLM04Data and Model Poisoning
MITRE ATLAS
  • AML.T0020Poison Training Data

Suggested from the entry's categories.

Cite

@misc{xiong2026mapleguard,
  title = {{MAPLE-Guard: Memory-Aware Link Enforcement Against Memory-Link Poisoning in Multi-Agent Systems}},
  author = {Wen-Jun Xiong and Yi-Jin Zhou and Jia-Qian Wang and Shangding Gu and Bo Tang and Zhiyu Li and Feiyu Xiong and Ying Wen and Muning Wen},
  year = {2026},
  month = aug,
  eprint = {2608.00426},
  archivePrefix = {arXiv},
  url = {https://www.semanticscholar.org/paper/758e18c7614f494fe9e97fa9c1eaeb32b4063d1f}
}