Single-Prompt Attack Plants Persistent AI Memory Instructions
🛡️ Researchers describe InjecMEM, an attack that plants hidden instructions in an AI agent’s memory with a single, ordinary prompt, causing the agent to reuse malicious content in future responses. The method targets memory systems that store past interactions, distinguishing itself from prompt injection by persisting across sessions. Evaluations on MemoryOS and MemGPT show high retrieval and attack success rates, exposing gaps in defenses that focus only on immediate inputs and outputs.
