🛰️ Daily AI Frontier
‹ back to 2026-08-24

InjecMEM: Memory Injection Attack on LLM Agent Memory Systems

Research LLM Agents

Ranking

Overall 84
Content 95
Popularity 59

Observed public metrics from 1 member.

Representative image for InjecMEM: Memory Injection Attack on LLM Agent Memory Systems

Merged summary

TL;DR - InjecMEM is a single-interaction memory injection attack that plants a retrievable record in an LLM agent’s persistent memory to steer later topic-related responses toward a chosen output. It exposes agent memory as a durable attack surface even without direct access to the memory store.

  • Combines a retriever-agnostic anchor with high-recall topical cues and an adversarial command that activates when the record is retrieved.
  • Optimizes the command using gradient-based coordinate search across synthetic prompt templates, insertion positions, and optionally multiple backbone models.
  • Remains effective across multiple memory systems and models under variable contexts, long prompts, and memory drift.
  • Targets related queries while reportedly leaving non-target queries unaffected, highlighting the need for memory-system defenses.

Sources (1)

InjecMEM: Memory Injection Attack on LLM Agent Memory Systems

arXiv cs.CR Hanling Tian, Gengyu Zhang, Zeyang Sha, Jingying Wang, Yuhang Liu, Zhehao Huang, Kun Yang, Xiaolin Huang 2026-08-24 arXiv:2608.23471
Public signals Hugging Face upvotes 1
Providers: Hugging Face · Upvotes 1 OpenAlex · N/A Publisher · N/A Semantic Scholar · N/A X · N/A Fetched 2026-09-22 14:32:24.458742 UTC

TL;DR - InjecMEM is a single-interaction memory injection attack that plants a retrievable record in an LLM agent’s persistent memory to steer later topic-related responses toward a chosen output. It exposes agent memory as a durable attack surface even without direct access to the memory store.

  • Combines a retriever-agnostic anchor with high-recall topical cues and an adversarial command that activates when the record is retrieved.
  • Optimizes the command using gradient-based coordinate search across synthetic prompt templates, insertion positions, and optionally multiple backbone models.
  • Remains effective across multiple memory systems and models under variable contexts, long prompts, and memory drift.
  • Targets related queries while reportedly leaving non-target queries unaffected, highlighting the need for memory-system defenses.
item →