Skip to content
Search
paper2026Unreviewed

PROMPT PERSISTENCE ATTACKS: LONG-TERM MEMORY POISONING IN LLM-BASED SYSTEMS

Pranav Bhatnagar

Abstract

Large Language Models (LLMs) are increasingly deployed as persistent, interactive systems that retain information across user interactions. These memory mechanisms are designed to enhance personalization, task continuity, and operational efficiency. However, persistence introduces a new and insufficiently examined security risk: the gradual corruption of long-term memory through legitimate interaction. This paper introduces the concept of Prompt Persistence Attacks, a class of long-horizon adver

Categories

Framework mappings

OWASP Top 10 for LLM Applications
  • LLM04Data and Model Poisoning
OWASP Top 10 for Agentic Applications
  • ASI06Memory & Context Poisoning
MITRE ATLAS
  • AML.T0020Poison Training Data
  • AML.T0080AI Agent Context Poisoning

Suggested from the entry's categories.

Cite

@misc{bhatnagar2026prompt,
  title = {{PROMPT PERSISTENCE ATTACKS: LONG-TERM MEMORY POISONING IN LLM-BASED SYSTEMS}},
  author = {Pranav Bhatnagar},
  year = {2026},
  doi = {10.2139/ssrn.6183548},
  url = {https://doi.org/10.2139/ssrn.6183548}
}