🛰️ Daily AI Frontier
‹ back to 2026-07-20

Do Agents Dream of False Memories? Black-box Visual Attacks on Long-term Memory in Multimodal AI Agents

arXiv cs.CR LLM Agents Halima Bouzidi, Mboutidem Ekemini Mkpong, Mohammad Abdullah Al Faruque 2026-07-17

TL;DR - Lucid is a black-box visual attack that uses imperceptible image perturbations to corrupt or inject long-term memories in multimodal AI agents. Its success across five memory architectures reveals a systemic risk in pipelines that implicitly trust visual inputs.

  • Requires no access to the target model, retrieval encoder, or text channel.
  • Memory poisoning exploits prior textual context to steer visual recall toward attacker-chosen narratives.
  • Memory injection targets turns without textual grounding, leaving no corrective memory signal.
  • Lucid achieved 61.6% attack success on poisoning and 58.4% on injection.

view merged work →