Visual Inception: Compromising Long-term Planning in Agentic Recommenders via Multimodal Memory Poisoning
Fuente:
arXiv
Saved in:
| Main Author: | Qian, Jiachen |
|---|---|
| Format: | Preprint |
| Published: |
2026
|
| Subjects: | |
| Online Access: | |
| Tags: |
Add Tag
No Tags, Be the first to tag this record!
|
Similar Items
MemoryGraft: Persistent Compromise of LLM Agents via Poisoned Experience Retrieval
by: Srivastava, Saksham Sahai, et al.
Published: (2025)
by: Srivastava, Saksham Sahai, et al.
Published: (2025)
Poison Once, Exploit Forever: Environment-Injected Memory Poisoning Attacks on Web Agents
by: Zou, Wei, et al.
Published: (2026)
by: Zou, Wei, et al.
Published: (2026)
SuperLocalMemory: Privacy-Preserving Multi-Agent Memory with Bayesian Trust Defense Against Memory Poisoning
by: Bhardwaj, Varun Pratap
Published: (2026)
by: Bhardwaj, Varun Pratap
Published: (2026)
ShadowMerge: A Novel Poisoning Attack on Graph-Based Agent Memory via Relation-Channel Conflicts
by: Luo, Yang, et al.
Published: (2026)
by: Luo, Yang, et al.
Published: (2026)
Hidden in the Metadata: Stealth Poisoning Attacks on Multimodal Retrieval-Augmented Generation
by: Edemacu, Kennedy, et al.
Published: (2026)
by: Edemacu, Kennedy, et al.
Published: (2026)
Poisoned Acoustics
by: Dahme, Harrison
Published: (2026)
by: Dahme, Harrison
Published: (2026)
MANA: Towards Efficient Mobile Ad Detection via Multimodal Agentic UI Navigation
by: Zhao, Yizhe, et al.
Published: (2026)
by: Zhao, Yizhe, et al.
Published: (2026)
Token by Token, Compromised: Backdoor Vulnerabilities in Unified Autoregressive Models
by: Braun, Tobias, et al.
Published: (2026)
by: Braun, Tobias, et al.
Published: (2026)
Poison Once, Control Anywhere: Clean-Text Visual Backdoors in VLM-based Mobile Agents
by: Wang, Xuan, et al.
Published: (2025)
by: Wang, Xuan, et al.
Published: (2025)
Reliable Model Watermarking: Defending Against Theft without Compromising on Evasion
by: Zhu, Hongyu, et al.
Published: (2024)
by: Zhu, Hongyu, et al.
Published: (2024)
On the Feasibility of Poisoning Text-to-Image AI Models via Adversarial Mislabeling
by: Wu, Stanley, et al.
Published: (2025)
by: Wu, Stanley, et al.
Published: (2025)
The Dark Side of LLMs: Agent-based Attack Vectors for System-level Compromise
by: Lupinacci, Matteo, et al.
Published: (2025)
by: Lupinacci, Matteo, et al.
Published: (2025)
BadSkill: Backdoor Attacks on Agent Skills via Model-in-Skill Poisoning
by: Tie, Guiyao, et al.
Published: (2026)
by: Tie, Guiyao, et al.
Published: (2026)
Toward Polymorphic Backdoor against Semantic Communication via Intensity-Based Poisoning
by: Yang, Xiao, et al.
Published: (2026)
by: Yang, Xiao, et al.
Published: (2026)
Persistent Pre-Training Poisoning of LLMs
by: Zhang, Yiming, et al.
Published: (2024)
by: Zhang, Yiming, et al.
Published: (2024)
On The Dangers of Poisoned LLMs In Security Automation
by: Karlsen, Patrick, et al.
Published: (2025)
by: Karlsen, Patrick, et al.
Published: (2025)
Cordon-MAS: Defending RAG against Knowledge Poisoning via Information-Flow Control
by: Yu, Zhe, et al.
Published: (2026)
by: Yu, Zhe, et al.
Published: (2026)
MoEcho: Exploiting Side-Channel Attacks to Compromise User Privacy in Mixture-of-Experts LLMs
by: Ding, Ruyi, et al.
Published: (2025)
by: Ding, Ruyi, et al.
Published: (2025)
CSC: Turning the Adversary's Poison against Itself
by: Shi, Yuchen, et al.
Published: (2026)
by: Shi, Yuchen, et al.
Published: (2026)
Data Poisoning in Deep Learning: A Survey
by: Zhao, Pinlong, et al.
Published: (2025)
by: Zhao, Pinlong, et al.
Published: (2025)
Sequential Comics for Jailbreaking Multimodal Large Language Models via Structured Visual Storytelling
by: Zhang, Deyue, et al.
Published: (2025)
by: Zhang, Deyue, et al.
Published: (2025)
Toward Trustworthy Agentic AI: A Multimodal Framework for Preventing Prompt Injection Attacks
by: Syed, Toqeer Ali, et al.
Published: (2025)
by: Syed, Toqeer Ali, et al.
Published: (2025)
LoopTrap: Termination Poisoning Attacks on LLM Agents
by: Xu, Huiyu, et al.
Published: (2026)
by: Xu, Huiyu, et al.
Published: (2026)
Poison to Detect: Detection of Targeted Overfitting in Federated Learning
by: Mestari, Soumia Zohra El, et al.
Published: (2025)
by: Mestari, Soumia Zohra El, et al.
Published: (2025)
On Protecting Agentic Systems' Intellectual Property via Watermarking
by: Wang, Liwen, et al.
Published: (2026)
by: Wang, Liwen, et al.
Published: (2026)
PADER: Paillier-based Secure Decentralized Social Recommendation
by: Chen, Chaochao, et al.
Published: (2026)
by: Chen, Chaochao, et al.
Published: (2026)
Compromising Embodied Agents with Contextual Backdoor Attacks
by: Liu, Aishan, et al.
Published: (2024)
by: Liu, Aishan, et al.
Published: (2024)
MCP-ITP: An Automated Framework for Implicit Tool Poisoning in MCP
by: Li, Ruiqi, et al.
Published: (2026)
by: Li, Ruiqi, et al.
Published: (2026)
From Poisoned to Aware: Fostering Backdoor Self-Awareness in LLMs
by: Shen, Guangyu, et al.
Published: (2025)
by: Shen, Guangyu, et al.
Published: (2025)
Turning Generative Models Degenerate: The Power of Data Poisoning Attacks
by: Jiang, Shuli, et al.
Published: (2024)
by: Jiang, Shuli, et al.
Published: (2024)
Defending Against Beta Poisoning Attacks in Machine Learning Models
by: Gulciftci, Nilufer, et al.
Published: (2025)
by: Gulciftci, Nilufer, et al.
Published: (2025)
Leverage Variational Graph Representation For Model Poisoning on Federated Learning
by: Li, Kai, et al.
Published: (2024)
by: Li, Kai, et al.
Published: (2024)
Human-Imperceptible Retrieval Poisoning Attacks in LLM-Powered Applications
by: Zhang, Quan, et al.
Published: (2024)
by: Zhang, Quan, et al.
Published: (2024)
When and Where do Data Poisons Attack Textual Inversion?
by: Styborski, Jeremy, et al.
Published: (2025)
by: Styborski, Jeremy, et al.
Published: (2025)
CBPF: Filtering Poisoned Data Based on Composite Backdoor Attack
by: Xia, Hanfeng, et al.
Published: (2024)
by: Xia, Hanfeng, et al.
Published: (2024)
Phantom Transfer: Data-level Defences are Insufficient Against Data Poisoning
by: Draganov, Andrew, et al.
Published: (2026)
by: Draganov, Andrew, et al.
Published: (2026)
Repurposing and Evaluating the (In)Feasibility of Dataset Poisoning enabled Watermarking for Contrastive Learning
by: Dai, Zhiyang, et al.
Published: (2026)
by: Dai, Zhiyang, et al.
Published: (2026)
Oracle Poisoning: Corrupting Knowledge Graphs to Weaponise AI Agent Reasoning
by: Kereopa-Yorke, Ben, et al.
Published: (2026)
by: Kereopa-Yorke, Ben, et al.
Published: (2026)
RouteGuard: Internal-Signal Detection of Skill Poisoning in LLM Agents
by: Xiao, Wenjie, et al.
Published: (2026)
by: Xiao, Wenjie, et al.
Published: (2026)
Knowledge Poisoning Attacks on Medical Multi-Modal Retrieval-Augmented Generation
by: Yang, Peiru, et al.
Published: (2026)
by: Yang, Peiru, et al.
Published: (2026)
Similar Items
-
MemoryGraft: Persistent Compromise of LLM Agents via Poisoned Experience Retrieval
by: Srivastava, Saksham Sahai, et al.
Published: (2025) -
Poison Once, Exploit Forever: Environment-Injected Memory Poisoning Attacks on Web Agents
by: Zou, Wei, et al.
Published: (2026) -
SuperLocalMemory: Privacy-Preserving Multi-Agent Memory with Bayesian Trust Defense Against Memory Poisoning
by: Bhardwaj, Varun Pratap
Published: (2026) -
ShadowMerge: A Novel Poisoning Attack on Graph-Based Agent Memory via Relation-Channel Conflicts
by: Luo, Yang, et al.
Published: (2026) -
Hidden in the Metadata: Stealth Poisoning Attacks on Multimodal Retrieval-Augmented Generation
by: Edemacu, Kennedy, et al.
Published: (2026)