Loading...
Agent Memory Poisoning
AMPInjection of malicious or manipulative information into an agent's long-term memory systems, corrupting its knowledge base and influencing future behaviors.
Example Scenario
Injecting false security policies into an agent's memory during initial conversations, causing it to bypass authentication checks in all future interactions, believing the false policy to be legitimate.
Testing Objectives
- Test memory validation mechanisms
- Assess storage integrity controls
- Evaluate memory isolation
- Validate knowledge source verification
Defensive Strategies
- Memory validation and sanitization
- Source verification for stored information
- Memory access controls
- Integrity checksums for stored data
- Periodic memory audits
Key Features
- Long-term memory corruption
- Knowledge base manipulation
- Persistent behavior modification
- Memory retrieval exploitation
Use Cases
- Memory integrity testing
- Knowledge base security assessment
- Memory validation evaluation
- Storage security testing
Tools & Frameworks
Security Risks
Ethical Guidelines
- •Only test memory systems with explicit authorization
- •Never poison production agent memories
- •Report memory vulnerabilities immediately
- •Focus on improving memory security
- •Consider long-term harm from corrupted memories
Remember: This information is for educational and defensive security purposes only. Always ensure you have proper authorization before testing any techniques.
From the engineer behind this catalog
Get your agent system red-teamed
The attacks documented here work on production agent systems every day. Have yours tested before someone else does: prompt injection, jailbreaks, tool misuse and data exfiltration, with every finding written up next to its fix.
€750 instead of €1,500, one week, written report and walkthrough call, until 30 September