[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-83883-en":3,"doc-seo-83883-105":30,"detail-sidebar-cat-0-en-105":91},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":21,"is_downloadable":21,"audit_status":21,"page_count":22,"language":23,"language_code":24,"site_id":25,"html_lang":24,"table_of_contents":26,"faqs":27,"seo_title":13,"seo_description":14,"update_tm":28,"read_time":29},83883,8796095461564,"Liam","https://ap-avatar.wpscdn.com/davatar_155a257f0dc6eb9ab79c44ca47cae57d",8,"Research & Report","Your Agent’s Memories Are Not Its Own: Forged Reasoning Attacks on LLM Agent Memory and Defenses","Persistent memory enables large language model (LLM) agents to retain factual knowledge, prior decisions, reasoning histories, tool usage, and task context, improving continuity but expanding the security attack surface. This work presents Forged Amplifying Rationale Memory Attack (FARMA), which poisons remembered reasoning traces using evasive language to bypass keyword defenses, then reinforces them through self-referential amplification that undermines consensus-based protections. A layered defense pipeline, SENTINEL, detects forged reasoning via a Reasoning Guard using five weighted signals. Across experiments, FARMA reaches up to 100% success under baseline settings, while SENTINEL reduces success to as low as 0% with no observed false positives.","Your Agent’s Memories Are Not Its Own: Forged Reasoning Attacks on LLM Agent Memory and  \nDefenses  \nNeeraj Karamchandani Piyush Nagasubramaniam  \nSencun Zhu Dinghao Wu  \nThe Pennsylvania State University, University Park, PA, USA  \n{njk5270,pvn5119,sxz16,[dinghao](dinghao}@psu.edu)[}](dinghao}@psu.edu)[@psu.edu](dinghao}@psu.edu)  \narXiv :2607 .05029v 1 [ cs .CR] 6 Jul 2026  \nAbstract—Persistent memory has enabled large language model (LLM) agents to store factual knowledge, prior decisions, reasoning histories, tool usage information, and context. While this has improved the agent’s functionality and continuity across tasks, it has also introduced a new attack surface: the agent’s own reasoning history. In this paper, we introduce the Forged Amplifying Rationale Memory Attack (FARMA), which poisons an agent’s remembered reasoning rather than its factual knowledge. It inserts forged reasoning traces using evasive language that bypasses keyword-based defenses, then amplifies them through self-referential reinforcement that defeats consensus-based defenses. To address FARMA, we introduce SENTINEL, a layered defense pipeline to detect forged reasoning entries. Its central component is the Reasoning Guard that structurally analyzes candidate entries for forgery using five weighted signals.  \nWe evaluate FARMA and SENTINEL across multiple agents and different LLM models with 50 trials and show that FARMA achieves an attack success rate of up to 100% under baseline conditions and is capable of defeating defense mechanisms like keyword filter and A-MemGuard. Our evaluation also shows that SENTINEL reduces FARMA’s attack success rate to as low as 0% with no false positives observed across 326 benign agent traces. Our work demonstrates the need to protect not only an agent’s retrieved content but also the integrity of its reasoning history.  \nIndex Terms—LLM agents, agentic security, memory poisoning, reasoning trace forgery, persistent memory, adversarial machine learning  \nI. INTRODUCTION  \nModern Large Language Model (LLM) based agents [1],[2] are becoming increasingly reliant on persistent memory to perform complex, multi-step tasks. Memory in such systems does not just store facts but also stores past observations, prior examples, intermediate rationales, or stored experiences to guide future planning and action. This persistence improves continuity and reduces redundant work, but it also introducesa new attack surface: the integrity of the agent’s own remembered reasoning. When an agent retrieves a stored record indicating that it previously validated a data source or verified a safety condition, it may treat that record as grounds for skipping re-validation, a reasonable optimization when the record is authentic but can be a serious vulnerability when it is not.  \nRecent disclosures show this is not a hypothetical concern but a real-world risk. SpAIware [3] demonstrated that adversarial entries can be written to ChatGPT’s persistent memory through indirect prompt injection, with the vulnerability requiring more than two months for OpenAI to patch. Salt Labs [4] documented OAuth flaws in ChatGPT plugins that grant unauthorized write access to user context. The OWASP Top 10 for Agentic Applications 2026 [5] also formally recognizes Memory and Context Poisoning (ASI06) as a deploymentrelevant attack class by itself, especially in multi-agent frameworks where shared memory stores turn one agent’s writes into another agent’s reads.  \nRecent research work has also demonstrated several forms of memory poisoning in agentic systems. AgentPoison [6] showed how a backdoor trigger can be embedded in an agent’s retrieval corpus. MINJA [7] showed that an attacker can induce an agent to store poisoned examples with the help of specially crafted queries. MemoryGraft [8] showed that injecting seemingly successful past experiences into longterm memory can bias future behavior. These types of attacks target different memory artifacts such as retr","cbCaisBSvooLG7re","https://ap.wps.com/l/cbCaisBSvooLG7re","pdf",294997,4,1,10,"English","en",105,"# Introduction\n## Threat background: persistent memory and reasoning integrity\n## Prior memory poisoning attacks and the gap\n## FARMA: forged reasoning injection and amplification\n# Defenses and evaluation","[{\"question\":\"What is the core vulnerability addressed in this paper?\",\"answer\":\"The paper targets integrity of an LLM agent’s stored reasoning history, where forged past rationale can cause the agent to skip necessary re-validation or safety checks.\"},{\"question\":\"How does FARMA conduct the attack?\",\"answer\":\"FARMA first injects forged reasoning/decision-log-like entries using evasive language to evade keyword-based defenses, then amplifies them by adding self-referential entries that increase retrieval probability and defeat consensus-based detection.\"},{\"question\":\"How does SENTINEL defend against forged reasoning entries?\",\"answer\":\"SENTINEL uses a layered pipeline centered on a Reasoning Guard that structurally analyzes candidate memory entries for forgery using five weighted signals, reducing FARMA success substantially.\"}]",1784191209,25,{"code":4,"msg":31,"data":32},"ok",{"site_id":25,"language":24,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":86,"head_meta":88,"extra_data":90,"updated_unix":28},"your-agents-memories-are-not-its-own-forged-reasoning-attacks-on-llm-agent-memory-and-defenses","",{"@graph":36,"@context":85},[37,53,68],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":21},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":50},"https://docshare.wps.com/document/research-report/",3,{"item":52,"name":13,"@type":43,"position":20},"https://docshare.wps.com/document/your-agents-memories-are-not-its-own-forged-reasoning-attacks-on-llm-agent-memory-and-defenses/83883/",{"url":52,"name":13,"@type":54,"author":55,"headline":13,"publisher":57,"fileFormat":60,"inLanguage":24,"description":14,"dateModified":61,"datePublished":62,"encodingFormat":60,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":56},"Person",{"url":41,"name":58,"@type":59},"DocShare","Organization","application/pdf","2026-07-27","2026-07-16",true,{"@type":65,"interactionType":66,"userInteractionCount":20},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81],{"name":72,"@type":73,"acceptedAnswer":74},"What is the core vulnerability addressed in this paper?","Question",{"text":75,"@type":76},"The paper targets integrity of an LLM agent’s stored reasoning history, where forged past rationale can cause the agent to skip necessary re-validation or safety checks.","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"How does FARMA conduct the attack?",{"text":80,"@type":76},"FARMA first injects forged reasoning/decision-log-like entries using evasive language to evade keyword-based defenses, then amplifies them by adding self-referential entries that increase retrieval probability and defeat consensus-based detection.",{"name":82,"@type":73,"acceptedAnswer":83},"How does SENTINEL defend against forged reasoning entries?",{"text":84,"@type":76},"SENTINEL uses a layered pipeline centered on a Reasoning Guard that structurally analyzes candidate memory entries for forgery using five weighted signals, reducing FARMA success substantially.","https://schema.org",{"og:url":52,"og:type":87,"og:title":13,"og:site_name":58,"og:description":14},"article",{"robots":89,"canonical":52},"index,follow",{"doc_id":7,"site_id":25},{"code":4,"msg":5,"data":92},[93,97,101,105,110,115,120,123,128,131,134],{"id":21,"doc_module":4,"doc_module_name":46,"category_name":94,"show_sort_weight":95,"slug":96},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":98,"show_sort_weight":99,"slug":100},"Literature",80,"literature",{"id":20,"doc_module":4,"doc_module_name":46,"category_name":102,"show_sort_weight":103,"slug":104},"Exam",70,"exam",{"id":106,"doc_module":4,"doc_module_name":46,"category_name":107,"show_sort_weight":108,"slug":109},5,"Comic",60,"comic",{"id":111,"doc_module":4,"doc_module_name":46,"category_name":112,"show_sort_weight":113,"slug":114},6,"Technology",50,"technology",{"id":116,"doc_module":4,"doc_module_name":46,"category_name":117,"show_sort_weight":118,"slug":119},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":121,"slug":122},30,"research-report",{"id":124,"doc_module":4,"doc_module_name":46,"category_name":125,"show_sort_weight":126,"slug":127},9,"Religion & Spirituality",20,"religion-spirituality",{"id":126,"doc_module":4,"doc_module_name":46,"category_name":129,"show_sort_weight":126,"slug":130},"World Cup","world-cup",{"id":22,"doc_module":4,"doc_module_name":46,"category_name":132,"show_sort_weight":22,"slug":133},"Lifestyle","lifestyle",{"id":135,"doc_module":4,"doc_module_name":46,"category_name":136,"show_sort_weight":106,"slug":137},19,"General","general"]