Memory Injection Attacks on LLM Agents via Query-Only Interaction
Fuente:
arXiv
Gespeichert in:
| Hauptverfasser: | Dong, Shen, Xu, Shaochen, He, Pengfei, Li, Yige, Tang, Jiliang, Liu, Tianming, Liu, Hui, Xiang, Zhen |
|---|---|
| Format: | Preprint |
| Veröffentlicht: |
2025
|
| Schlagworte: | |
| Online-Zugang: | |
| Tags: |
Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
|
Ähnliche Einträge
Multi-Faceted Studies on Data Poisoning can Advance LLM Development
von: He, Pengfei, et al.
Veröffentlicht: (2025)
von: He, Pengfei, et al.
Veröffentlicht: (2025)
ATOM: A Framework of Detecting Query-Based Model Extraction Attacks for Graph Neural Networks
von: Cheng, Zhan, et al.
Veröffentlicht: (2025)
von: Cheng, Zhan, et al.
Veröffentlicht: (2025)
Towards the Effect of Examples on In-Context Learning: A Theoretical Case Study
von: He, Pengfei, et al.
Veröffentlicht: (2024)
von: He, Pengfei, et al.
Veröffentlicht: (2024)
Query-Based and Unnoticeable Graph Injection Attack from Neighborhood Perspective
von: Liu, Chang, et al.
Veröffentlicht: (2025)
von: Liu, Chang, et al.
Veröffentlicht: (2025)
PIShield: Detecting Prompt Injection Attacks via Intrinsic LLM Features
von: Zou, Wei, et al.
Veröffentlicht: (2025)
von: Zou, Wei, et al.
Veröffentlicht: (2025)
PEAR: Planner-Executor Agent Robustness Benchmark
von: Dong, Shen, et al.
Veröffentlicht: (2025)
von: Dong, Shen, et al.
Veröffentlicht: (2025)
AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases
von: Chen, Zhaorun, et al.
Veröffentlicht: (2024)
von: Chen, Zhaorun, et al.
Veröffentlicht: (2024)
Adaptive Attacks Break Defenses Against Indirect Prompt Injection Attacks on LLM Agents
von: Zhan, Qiusi, et al.
Veröffentlicht: (2025)
von: Zhan, Qiusi, et al.
Veröffentlicht: (2025)
Unveiling Privacy Risks in LLM Agent Memory
von: Wang, Bo, et al.
Veröffentlicht: (2025)
von: Wang, Bo, et al.
Veröffentlicht: (2025)
Chain-of-Memory: Lightweight Memory Construction with Dynamic Evolution for LLM Agents
von: Xu, Xiucheng, et al.
Veröffentlicht: (2026)
von: Xu, Xiucheng, et al.
Veröffentlicht: (2026)
Co-RedTeam: Orchestrated Security Discovery and Exploitation with LLM Agents
von: He, Pengfei, et al.
Veröffentlicht: (2026)
von: He, Pengfei, et al.
Veröffentlicht: (2026)
ER-MIA: Black-Box Adversarial Memory Injection Attacks on Long-Term Memory-Augmented Large Language Models
von: Piehl, Mitchell, et al.
Veröffentlicht: (2026)
von: Piehl, Mitchell, et al.
Veröffentlicht: (2026)
A Multi-Agent LLM Defense Pipeline Against Prompt Injection Attacks
von: Hossain, S M Asif, et al.
Veröffentlicht: (2025)
von: Hossain, S M Asif, et al.
Veröffentlicht: (2025)
AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents
von: Debenedetti, Edoardo, et al.
Veröffentlicht: (2024)
von: Debenedetti, Edoardo, et al.
Veröffentlicht: (2024)
Towards Universal and Black-Box Query-Response Only Attack on LLMs with QROA
von: Jawad, Hussein, et al.
Veröffentlicht: (2024)
von: Jawad, Hussein, et al.
Veröffentlicht: (2024)
Adversarial Contrastive Learning for LLM Quantization Attacks
von: Song, Dinghong, et al.
Veröffentlicht: (2026)
von: Song, Dinghong, et al.
Veröffentlicht: (2026)
Test-Time Adaptation for LLM Agents via Environment Interaction
von: Chen, Arthur, et al.
Veröffentlicht: (2025)
von: Chen, Arthur, et al.
Veröffentlicht: (2025)
Continual Learning with Query-Only Attention
von: Bekal, Gautham, et al.
Veröffentlicht: (2025)
von: Bekal, Gautham, et al.
Veröffentlicht: (2025)
MeKi: Memory-based Expert Knowledge Injection for Efficient LLM Scaling
von: Ding, Ning, et al.
Veröffentlicht: (2026)
von: Ding, Ning, et al.
Veröffentlicht: (2026)
Revisiting Label Inference Attacks in Vertical Federated Learning: Why They Are Vulnerable and How to Defend
von: Liu, Yige, et al.
Veröffentlicht: (2026)
von: Liu, Yige, et al.
Veröffentlicht: (2026)
Superiority of Multi-Head Attention in In-Context Linear Regression
von: Cui, Yingqian, et al.
Veröffentlicht: (2024)
von: Cui, Yingqian, et al.
Veröffentlicht: (2024)
Adaptive Test-Time Reasoning via Reward-Guided Dual-Phase Search
von: Cui, Yingqian, et al.
Veröffentlicht: (2025)
von: Cui, Yingqian, et al.
Veröffentlicht: (2025)
Prompt Injection Attacks on LLM Generated Reviews of Scientific Publications
von: Keuper, Janis
Veröffentlicht: (2025)
von: Keuper, Janis
Veröffentlicht: (2025)
DiffusionShield: A Watermark for Copyright Protection against Generative Diffusion Models
von: Cui, Yingqian, et al.
Veröffentlicht: (2023)
von: Cui, Yingqian, et al.
Veröffentlicht: (2023)
Make LLMs better zero-shot reasoners: Structure-orientated autonomous reasoning
von: He, Pengfei, et al.
Veröffentlicht: (2024)
von: He, Pengfei, et al.
Veröffentlicht: (2024)
A Simple Plug-in for Improving Eviction-Based KV Cache Compression
von: Lin, Yuping, et al.
Veröffentlicht: (2026)
von: Lin, Yuping, et al.
Veröffentlicht: (2026)
Red-Teaming LLM Multi-Agent Systems via Communication Attacks
von: He, Pengfei, et al.
Veröffentlicht: (2025)
von: He, Pengfei, et al.
Veröffentlicht: (2025)
Visual Memory Injection Attacks for Multi-Turn Conversations
von: Schlarmann, Christian, et al.
Veröffentlicht: (2026)
von: Schlarmann, Christian, et al.
Veröffentlicht: (2026)
IterInject: Indirect Prompt Injection Against LLM Agents via Feedback-Guided Iterative Optimization
von: Chen, Zixuan, et al.
Veröffentlicht: (2026)
von: Chen, Zixuan, et al.
Veröffentlicht: (2026)
Understanding and Alleviating Memory Consumption in RLHF for LLMs
von: Zhou, Jin, et al.
Veröffentlicht: (2024)
von: Zhou, Jin, et al.
Veröffentlicht: (2024)
LLM Unlearning via Loss Adjustment with Only Forget Data
von: Wang, Yaxuan, et al.
Veröffentlicht: (2024)
von: Wang, Yaxuan, et al.
Veröffentlicht: (2024)
How Memory Management Impacts LLM Agents: An Empirical Study of Experience-Following Behavior
von: Xiong, Zidi, et al.
Veröffentlicht: (2025)
von: Xiong, Zidi, et al.
Veröffentlicht: (2025)
Apollo: A Posteriori Label-Only Membership Inference Attack Towards Machine Unlearning
von: Tang, Liou, et al.
Veröffentlicht: (2025)
von: Tang, Liou, et al.
Veröffentlicht: (2025)
Exploratory Memory-Augmented LLM Agent via Hybrid On- and Off-Policy Optimization
von: Liu, Zeyuan, et al.
Veröffentlicht: (2026)
von: Liu, Zeyuan, et al.
Veröffentlicht: (2026)
Is the Trigger Essential? A Feature-Based Triggerless Backdoor Attack in Vertical Federated Learning
von: Liu, Yige, et al.
Veröffentlicht: (2026)
von: Liu, Yige, et al.
Veröffentlicht: (2026)
Crafting Reversible SFT Behaviors in Large Language Models
von: Lin, Yuping, et al.
Veröffentlicht: (2026)
von: Lin, Yuping, et al.
Veröffentlicht: (2026)
Winner-Take-All Column Row Sampling for Memory Efficient Adaptation of Language Model
von: Liu, Zirui, et al.
Veröffentlicht: (2023)
von: Liu, Zirui, et al.
Veröffentlicht: (2023)
Measuring Real-World Prompt Injection Attacks in LLM-based Resume Screening
von: Zhang, Mohan, et al.
Veröffentlicht: (2026)
von: Zhang, Mohan, et al.
Veröffentlicht: (2026)
A Theoretical Understanding of Chain-of-Thought: Coherent Reasoning and Error-Aware Demonstration
von: Cui, Yingqian, et al.
Veröffentlicht: (2024)
von: Cui, Yingqian, et al.
Veröffentlicht: (2024)
MemoryGraft: Persistent Compromise of LLM Agents via Poisoned Experience Retrieval
von: Srivastava, Saksham Sahai, et al.
Veröffentlicht: (2025)
von: Srivastava, Saksham Sahai, et al.
Veröffentlicht: (2025)
Ähnliche Einträge
-
Multi-Faceted Studies on Data Poisoning can Advance LLM Development
von: He, Pengfei, et al.
Veröffentlicht: (2025) -
ATOM: A Framework of Detecting Query-Based Model Extraction Attacks for Graph Neural Networks
von: Cheng, Zhan, et al.
Veröffentlicht: (2025) -
Towards the Effect of Examples on In-Context Learning: A Theoretical Case Study
von: He, Pengfei, et al.
Veröffentlicht: (2024) -
Query-Based and Unnoticeable Graph Injection Attack from Neighborhood Perspective
von: Liu, Chang, et al.
Veröffentlicht: (2025) -
PIShield: Detecting Prompt Injection Attacks via Intrinsic LLM Features
von: Zou, Wei, et al.
Veröffentlicht: (2025)