[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-84932-en":3,"doc-seo-84932-105":30,"detail-sidebar-cat-0-en-105":91},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":21,"is_downloadable":21,"audit_status":21,"page_count":22,"language":23,"language_code":24,"site_id":25,"html_lang":24,"table_of_contents":26,"faqs":27,"seo_title":13,"seo_description":14,"update_tm":28,"read_time":29},84932,687197207639,"Asher","https://ap-avatar.wpscdn.com/davatar_a8503ba1806abce46bf441b54a3ca4cd",8,"Research & Report","When Agents Remember Too Much Memory Poisoning Attacks on Large Language Model Agents","Personal AI agents powered by large language models can reason and act with minimal oversight, using tools such as email, calendars, and code repositories. Adding long-term memory reduces reliance on large context windows by recalling task-relevant details, but also introduces security risks when agents ingest untrusted information. The paper presents GhostWriter, a two-phase attack (injection and activation) that poisons tool-using agents’ memory and then triggers retrieval. Experiments show ~98% injection and ~60% activation success, motivating AM-Sentry mitigations.","When Agents Remember Too Much: Memory Poisoning Attacks on Large Language  \nModel Agents  \nGeorge Torres‡, Sharad Shrestha∗ , and Satyajayant Misra§  \n‡∗§ Department of Computer Science, § Klipsch School of Electrical and Computer Engineering  \nNew Mexico State University, Las Cruces, New Mexico, USA  \nEmail:‡[gtorrez@nmsu.edu](gtorrez@nmsu.edu),∗[sharad@nmsu.edu](sharad@nmsu.edu),§[misra@nmsu.edu](misra@nmsu.edu)  \narXiv :2607 .06595v 1 [ cs .CR] 6 Jul 2026  \nAbstract—Personal AI agents powered by large language models can reason and act using available tools to access emails, manage calendars, and push code to remote repositories, all with minimal oversight. When augmented with long-term memory, an agent can recall specific details relevant to the current task, reducing the need for large context windows. Currently, long-term memory agents tend to fall into two distinct domains: conversational and action-planning agents. Personal assistant agents sit at the convergence of these two domains and handle sensitive information while interacting with untrusted information sources, creating previously unaccounted security vulnerabilities. In this work, we introduce the novel attack vector, GhostWriter, which exploits current memory subsystems in tool-using personal agents to poison their memory store. GhostWriter operates in two phases: injection, where an adversary sends a hidden attack payload to the target agent; and activation, in which the poisoned memory is retrieved. We show that GhostWriter achieves near-universal injection rates of approximately 98% and a high average activation rate of approximately 60% against state-of-the-art agents. This attack is possible due to the lack of securityfocused memory governance. In response, we propose Agentic Memory Sentry (AM-Sentry), which leverages two mitigation techniques: a memory-saving policy and a memory-retrieval screen. Our experiments show that AM-Sentry dramatically reduces GhostWriter’s success rate while preserving agent utility.  \n1. Introduction  \nLarge language model (LLM) agents can reason and act with minimal human oversight, enabling automation of complex, multi-step tasks. These agents have access to tools that improve their efficiency and agency, allowing them to access emails, reply to calendar invites, and even push code to remote repositories [1], [2] . An agent’s reasoning, decision-making, and accuracy can be further improved through the integration of long-term memory [3], [4] . An agent with long-term memory can recall specific details relevant to its current task, reducing the need for large context windows that do not scale well. Figure 1 illustrates this with an example: across sessions or after long periods between related tasks, an agent with only its context window  \n\n| Stateless LLM Agents\u003Cbr>\u003Cbr> | Add\u003Cbr>memory layer\u003Cbr> | LLM with Persistent Memory (Knowledgeable Partner)\u003Cbr>\u003Cbr>\u003Cbr>\u003Cbr>Store New Facts\u003Cbr>Context-aware responses drawn from accumulated history. |\n| --- | --- | --- |\n| No context retained\u003Cbr>between sessions. |  |  |\n\n|  |  |\n| --- | --- |\n\nFigure 1: Stateless LLM agents process each interaction in isolation. LLM agents with persistent memory allow for querying and retrieving saved information.  \nstruggles to accurately answer the user’s question and may even hallucinate. In contrast, the agent equipped with a longterm memory store can dynamically retrieve the necessary context and accurately answer the given question.  \nThe existing literature on agents with long-term memory has primarily been split into two distinct domains: conversational agents (i.e., chatbots) [3], [5], whose primary role is to talk with a user, and action-planning agents [4], [6], which focus on improving tool use or other complex operations, such as robotic control or code execution. Practical use cases that combine aspects of both domains, such as personal assistant agents or automated coding agents [7], [8], are currently underrepresented, and these agents w","cbCaiutxf5EBtV6q","https://ap.wps.com/l/cbCaiutxf5EBtV6q","pdf",3080537,3,1,17,"English","en",105,"# Abstract\n# Introduction\n## Long-term memory in LLM agents\n## Security risks from untrusted information\n## Prior work on memory corruption\n# GhostWriter attack concept\n## Injection phase\n## Activation phase\n# Proposed mitigation: AM-Sentry\n## Memory-saving policy\n## Memory-retrieval screen","[{\"question\":\"What problem does the paper address about long-term memory in LLM agents?\",\"answer\":\"Long-term memory improves agents by retrieving task-relevant details, but it creates new security vulnerabilities when agents store and later use information from untrusted sources.\"},{\"question\":\"How does the GhostWriter attack work?\",\"answer\":\"GhostWriter runs in two phases: injection, where an attacker sends a hidden payload to poison the agent’s memory store, and activation, where the poisoned memory is retrieved and used to alter behavior.\"},{\"question\":\"What mitigation does the paper propose and what does it achieve?\",\"answer\":\"The paper proposes Agentic Memory Sentry (AM-Sentry), using a memory-saving policy and a memory-retrieval screen. Experiments show it substantially reduces GhostWriter’s success rate while preserving agent utility.\"}]",1784199453,43,{"code":4,"msg":31,"data":32},"ok",{"site_id":25,"language":24,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":86,"head_meta":88,"extra_data":90,"updated_unix":28},"when-agents-remember-too-much-memory-poisoning-attacks-on-large-language-model-agents","",{"@graph":36,"@context":85},[37,53,68],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,50],{"item":41,"name":42,"@type":43,"position":21},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":20},"https://docshare.wps.com/document/research-report/",{"item":51,"name":13,"@type":43,"position":52},"https://docshare.wps.com/document/when-agents-remember-too-much-memory-poisoning-attacks-on-large-language-model-agents/84932/",4,{"url":51,"name":13,"@type":54,"author":55,"headline":13,"publisher":57,"fileFormat":60,"inLanguage":24,"description":14,"dateModified":61,"datePublished":62,"encodingFormat":60,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":56},"Person",{"url":41,"name":58,"@type":59},"DocShare","Organization","application/pdf","2026-07-23","2026-07-16",true,{"@type":65,"interactionType":66,"userInteractionCount":20},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81],{"name":72,"@type":73,"acceptedAnswer":74},"What problem does the paper address about long-term memory in LLM agents?","Question",{"text":75,"@type":76},"Long-term memory improves agents by retrieving task-relevant details, but it creates new security vulnerabilities when agents store and later use information from untrusted sources.","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"How does the GhostWriter attack work?",{"text":80,"@type":76},"GhostWriter runs in two phases: injection, where an attacker sends a hidden payload to poison the agent’s memory store, and activation, where the poisoned memory is retrieved and used to alter behavior.",{"name":82,"@type":73,"acceptedAnswer":83},"What mitigation does the paper propose and what does it achieve?",{"text":84,"@type":76},"The paper proposes Agentic Memory Sentry (AM-Sentry), using a memory-saving policy and a memory-retrieval screen. Experiments show it substantially reduces GhostWriter’s success rate while preserving agent utility.","https://schema.org",{"og:url":51,"og:type":87,"og:title":13,"og:site_name":58,"og:description":14},"article",{"robots":89,"canonical":51},"index,follow",{"doc_id":7,"site_id":25},{"code":4,"msg":5,"data":92},[93,97,101,105,110,115,120,123,128,131,135],{"id":21,"doc_module":4,"doc_module_name":46,"category_name":94,"show_sort_weight":95,"slug":96},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":98,"show_sort_weight":99,"slug":100},"Literature",80,"literature",{"id":52,"doc_module":4,"doc_module_name":46,"category_name":102,"show_sort_weight":103,"slug":104},"Exam",70,"exam",{"id":106,"doc_module":4,"doc_module_name":46,"category_name":107,"show_sort_weight":108,"slug":109},5,"Comic",60,"comic",{"id":111,"doc_module":4,"doc_module_name":46,"category_name":112,"show_sort_weight":113,"slug":114},6,"Technology",50,"technology",{"id":116,"doc_module":4,"doc_module_name":46,"category_name":117,"show_sort_weight":118,"slug":119},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":121,"slug":122},30,"research-report",{"id":124,"doc_module":4,"doc_module_name":46,"category_name":125,"show_sort_weight":126,"slug":127},9,"Religion & Spirituality",20,"religion-spirituality",{"id":126,"doc_module":4,"doc_module_name":46,"category_name":129,"show_sort_weight":126,"slug":130},"World Cup","world-cup",{"id":132,"doc_module":4,"doc_module_name":46,"category_name":133,"show_sort_weight":132,"slug":134},10,"Lifestyle","lifestyle",{"id":136,"doc_module":4,"doc_module_name":46,"category_name":137,"show_sort_weight":106,"slug":138},19,"General","general"]