Memory Poisoning

Persistent memory lets agents remember preferences, facts, and past work. It also gives attackers a way to make a single injection last, turning a one-time compromise into an ongoing one.

Memory poisoning techniques include:

  • Injected memories: Prompts that instruct the agent to save attacker-chosen facts.
  • False preferences: Fake user preferences that redirect future actions.
  • Poisoned summaries: Malicious content preserved through conversation summarization.
  • Shared memory abuse: Corrupting memory stores used by multiple agents or users.
  • Dormant triggers: Instructions that activate only under later conditions.

Poisoned memory is difficult to spot because it looks like legitimate context. Users may never see what the agent remembers, and the malicious effect can appear weeks later in an unrelated task.

Defenses include validating what gets written to memory, attributing memories to their source, letting users review stored memories, and monitoring for behavior changes after memory updates. OWASP tracks the risk as ASI06.

How PointGuard AI Helps

PointGuard AI AI Runtime Guardrails inspect content before it is committed to agent memory, and Guardian Agent monitoring detects behavioral shifts that suggest poisoned context. Agent Mission Control keeps actions within mission boundaries even if memory is corrupted.

Learn More

Ready to get started?

Our expert team can assess your needs, show you a live demo, and recommend a solution that will save you time and money.