Researchers expose GhostWriter attack that poisons AI agents' long‑term memory
Summary
Scientists at New Mexico State University have demonstrated a new attack, dubbed GhostWriter, that can silently inject false memories into large‑language‑model (LLM) agents with persistent memory. In tests the attack succeeded in inserting malicious data about 98% of the time and later activated the poisoned memory in roughly 60% of interactions. The technique targets the memory subsystem rather than the model itself, allowing the manipulation to persist across sessions. Researchers also proposed a defensive framework, Agentic Memory Sentry (AM‑Sentry), which markedly lowers the attack’s success while keeping the agent functional. The findings raise urgent security concerns as AI assistants with long‑term memory become widespread.
Sources
2 sources- Hidden prompts can secretly rewrite an AI’s memory, and researchers say that’s a serious problem
digitaltrends.com - Technology / 2026-07-19T23:36:43+00:00