Memory Injection Attacks on LLM Agents via Query-Only Interaction
Fuente:
arXiv
Salvato in:
| Autori principali: | Dong, Shen, Xu, Shaochen, He, Pengfei, Li, Yige, Tang, Jiliang, Liu, Tianming, Liu, Hui, Xiang, Zhen |
|---|---|
| Natura: | Preprint |
| Pubblicazione: |
2025
|
| Soggetti: | |
| Accesso online: | |
| Tags: |
Aggiungi Tag
Nessun Tag, puoi essere il primo ad aggiungerne!!
|
Documenti analoghi
Multi-Faceted Studies on Data Poisoning can Advance LLM Development
di: He, Pengfei, et al.
Pubblicazione: (2025)
di: He, Pengfei, et al.
Pubblicazione: (2025)
ATOM: A Framework of Detecting Query-Based Model Extraction Attacks for Graph Neural Networks
di: Cheng, Zhan, et al.
Pubblicazione: (2025)
di: Cheng, Zhan, et al.
Pubblicazione: (2025)
Towards the Effect of Examples on In-Context Learning: A Theoretical Case Study
di: He, Pengfei, et al.
Pubblicazione: (2024)
di: He, Pengfei, et al.
Pubblicazione: (2024)
Query-Based and Unnoticeable Graph Injection Attack from Neighborhood Perspective
di: Liu, Chang, et al.
Pubblicazione: (2025)
di: Liu, Chang, et al.
Pubblicazione: (2025)
PIShield: Detecting Prompt Injection Attacks via Intrinsic LLM Features
di: Zou, Wei, et al.
Pubblicazione: (2025)
di: Zou, Wei, et al.
Pubblicazione: (2025)
PEAR: Planner-Executor Agent Robustness Benchmark
di: Dong, Shen, et al.
Pubblicazione: (2025)
di: Dong, Shen, et al.
Pubblicazione: (2025)
AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases
di: Chen, Zhaorun, et al.
Pubblicazione: (2024)
di: Chen, Zhaorun, et al.
Pubblicazione: (2024)
Adaptive Attacks Break Defenses Against Indirect Prompt Injection Attacks on LLM Agents
di: Zhan, Qiusi, et al.
Pubblicazione: (2025)
di: Zhan, Qiusi, et al.
Pubblicazione: (2025)
Unveiling Privacy Risks in LLM Agent Memory
di: Wang, Bo, et al.
Pubblicazione: (2025)
di: Wang, Bo, et al.
Pubblicazione: (2025)
Chain-of-Memory: Lightweight Memory Construction with Dynamic Evolution for LLM Agents
di: Xu, Xiucheng, et al.
Pubblicazione: (2026)
di: Xu, Xiucheng, et al.
Pubblicazione: (2026)
Co-RedTeam: Orchestrated Security Discovery and Exploitation with LLM Agents
di: He, Pengfei, et al.
Pubblicazione: (2026)
di: He, Pengfei, et al.
Pubblicazione: (2026)
ER-MIA: Black-Box Adversarial Memory Injection Attacks on Long-Term Memory-Augmented Large Language Models
di: Piehl, Mitchell, et al.
Pubblicazione: (2026)
di: Piehl, Mitchell, et al.
Pubblicazione: (2026)
A Multi-Agent LLM Defense Pipeline Against Prompt Injection Attacks
di: Hossain, S M Asif, et al.
Pubblicazione: (2025)
di: Hossain, S M Asif, et al.
Pubblicazione: (2025)
AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents
di: Debenedetti, Edoardo, et al.
Pubblicazione: (2024)
di: Debenedetti, Edoardo, et al.
Pubblicazione: (2024)
Towards Universal and Black-Box Query-Response Only Attack on LLMs with QROA
di: Jawad, Hussein, et al.
Pubblicazione: (2024)
di: Jawad, Hussein, et al.
Pubblicazione: (2024)
Adversarial Contrastive Learning for LLM Quantization Attacks
di: Song, Dinghong, et al.
Pubblicazione: (2026)
di: Song, Dinghong, et al.
Pubblicazione: (2026)
Test-Time Adaptation for LLM Agents via Environment Interaction
di: Chen, Arthur, et al.
Pubblicazione: (2025)
di: Chen, Arthur, et al.
Pubblicazione: (2025)
Continual Learning with Query-Only Attention
di: Bekal, Gautham, et al.
Pubblicazione: (2025)
di: Bekal, Gautham, et al.
Pubblicazione: (2025)
MeKi: Memory-based Expert Knowledge Injection for Efficient LLM Scaling
di: Ding, Ning, et al.
Pubblicazione: (2026)
di: Ding, Ning, et al.
Pubblicazione: (2026)
Revisiting Label Inference Attacks in Vertical Federated Learning: Why They Are Vulnerable and How to Defend
di: Liu, Yige, et al.
Pubblicazione: (2026)
di: Liu, Yige, et al.
Pubblicazione: (2026)
Superiority of Multi-Head Attention in In-Context Linear Regression
di: Cui, Yingqian, et al.
Pubblicazione: (2024)
di: Cui, Yingqian, et al.
Pubblicazione: (2024)
Adaptive Test-Time Reasoning via Reward-Guided Dual-Phase Search
di: Cui, Yingqian, et al.
Pubblicazione: (2025)
di: Cui, Yingqian, et al.
Pubblicazione: (2025)
Prompt Injection Attacks on LLM Generated Reviews of Scientific Publications
di: Keuper, Janis
Pubblicazione: (2025)
di: Keuper, Janis
Pubblicazione: (2025)
DiffusionShield: A Watermark for Copyright Protection against Generative Diffusion Models
di: Cui, Yingqian, et al.
Pubblicazione: (2023)
di: Cui, Yingqian, et al.
Pubblicazione: (2023)
Make LLMs better zero-shot reasoners: Structure-orientated autonomous reasoning
di: He, Pengfei, et al.
Pubblicazione: (2024)
di: He, Pengfei, et al.
Pubblicazione: (2024)
A Simple Plug-in for Improving Eviction-Based KV Cache Compression
di: Lin, Yuping, et al.
Pubblicazione: (2026)
di: Lin, Yuping, et al.
Pubblicazione: (2026)
Red-Teaming LLM Multi-Agent Systems via Communication Attacks
di: He, Pengfei, et al.
Pubblicazione: (2025)
di: He, Pengfei, et al.
Pubblicazione: (2025)
Visual Memory Injection Attacks for Multi-Turn Conversations
di: Schlarmann, Christian, et al.
Pubblicazione: (2026)
di: Schlarmann, Christian, et al.
Pubblicazione: (2026)
IterInject: Indirect Prompt Injection Against LLM Agents via Feedback-Guided Iterative Optimization
di: Chen, Zixuan, et al.
Pubblicazione: (2026)
di: Chen, Zixuan, et al.
Pubblicazione: (2026)
Understanding and Alleviating Memory Consumption in RLHF for LLMs
di: Zhou, Jin, et al.
Pubblicazione: (2024)
di: Zhou, Jin, et al.
Pubblicazione: (2024)
LLM Unlearning via Loss Adjustment with Only Forget Data
di: Wang, Yaxuan, et al.
Pubblicazione: (2024)
di: Wang, Yaxuan, et al.
Pubblicazione: (2024)
How Memory Management Impacts LLM Agents: An Empirical Study of Experience-Following Behavior
di: Xiong, Zidi, et al.
Pubblicazione: (2025)
di: Xiong, Zidi, et al.
Pubblicazione: (2025)
Apollo: A Posteriori Label-Only Membership Inference Attack Towards Machine Unlearning
di: Tang, Liou, et al.
Pubblicazione: (2025)
di: Tang, Liou, et al.
Pubblicazione: (2025)
Exploratory Memory-Augmented LLM Agent via Hybrid On- and Off-Policy Optimization
di: Liu, Zeyuan, et al.
Pubblicazione: (2026)
di: Liu, Zeyuan, et al.
Pubblicazione: (2026)
Is the Trigger Essential? A Feature-Based Triggerless Backdoor Attack in Vertical Federated Learning
di: Liu, Yige, et al.
Pubblicazione: (2026)
di: Liu, Yige, et al.
Pubblicazione: (2026)
Crafting Reversible SFT Behaviors in Large Language Models
di: Lin, Yuping, et al.
Pubblicazione: (2026)
di: Lin, Yuping, et al.
Pubblicazione: (2026)
Winner-Take-All Column Row Sampling for Memory Efficient Adaptation of Language Model
di: Liu, Zirui, et al.
Pubblicazione: (2023)
di: Liu, Zirui, et al.
Pubblicazione: (2023)
Measuring Real-World Prompt Injection Attacks in LLM-based Resume Screening
di: Zhang, Mohan, et al.
Pubblicazione: (2026)
di: Zhang, Mohan, et al.
Pubblicazione: (2026)
A Theoretical Understanding of Chain-of-Thought: Coherent Reasoning and Error-Aware Demonstration
di: Cui, Yingqian, et al.
Pubblicazione: (2024)
di: Cui, Yingqian, et al.
Pubblicazione: (2024)
MemoryGraft: Persistent Compromise of LLM Agents via Poisoned Experience Retrieval
di: Srivastava, Saksham Sahai, et al.
Pubblicazione: (2025)
di: Srivastava, Saksham Sahai, et al.
Pubblicazione: (2025)
Documenti analoghi
-
Multi-Faceted Studies on Data Poisoning can Advance LLM Development
di: He, Pengfei, et al.
Pubblicazione: (2025) -
ATOM: A Framework of Detecting Query-Based Model Extraction Attacks for Graph Neural Networks
di: Cheng, Zhan, et al.
Pubblicazione: (2025) -
Towards the Effect of Examples on In-Context Learning: A Theoretical Case Study
di: He, Pengfei, et al.
Pubblicazione: (2024) -
Query-Based and Unnoticeable Graph Injection Attack from Neighborhood Perspective
di: Liu, Chang, et al.
Pubblicazione: (2025) -
PIShield: Detecting Prompt Injection Attacks via Intrinsic LLM Features
di: Zou, Wei, et al.
Pubblicazione: (2025)