Attackers exploit an agent's reliance on short- or long-term memory to inject malicious or false data, corrupting future decisions, bypassing security checks, or escalating privilege via memory recall. In a multi-agent system: A shared-memory travel-booking agent has a false 'chartered flights are free' pricing rule repeatedly reinforced by an attacker, unti…
Use this profile to understand the building block briefly, place it in the model, and switch to the 360° assessment when needed.
Theoretical construct: explains a term, principle, or mental model.
What organizes, connects, or makes decisions possible.
Memory poisoning deliberately inserts false or harmful information into an AI system's long-term context so later answers or actions are manipulated.
The term applies classic data and model poisoning to agentic systems with persistent memory. OWASP presents memory poisoning as a risk for LLM applications and explains how manipulated memories can later act as trusted context.
Imagine a forged note in an assistant's notebook that it treats as true on every later assignment. One stored sentence can steer many decisions after its original source has disappeared.
Manipulated information survives beyond a single request.
Later tasks load poisoned information as seemingly relevant context.
Stored content needs a source, trust level, and change history.
Memory poisoning turns memory into a security boundary and calls for validation, cleanup, and traceable provenance of stored content.
Where this building block is located in the topic model.
No structure path available.
Explore how this building block connects to concepts, methods, technologies, and tools.
These sources establish the term and its professional meaning.
All direct connections of the current building block in a compact text view.
This classification shows where the building block typically matters, how demanding it is, and what kind of impact it has in the model.
The level within the organization (enterprise, domain, team) at which the AssetBlock is applied.