Transferable End-to-End Optimization for Indirect Long-Term Memory Poisoning in LLM Agents

📅 2026-08-31
📈 Citations: 0
Influential: 0
📄 PDF
🤖 AI Summary
本文针对间接长期记忆中毒问题,提出PipePoison方法,通过端到端优化各阶段瓶颈,提高攻击利用率和跨配置迁移性。
📝 Abstract
Long-term memory can turn untrusted external content into persistent influence over an LLM agent's future decisions, creating the threat of indirect memory poisoning. A successful attack must survive a multi-stage pipeline comprising memory writing, retrieval, and utilization. Existing attacks largely rely on intra-stage optimization, optimizing individual stages in isolation while overlooking inter-stage coupling. Specifically, these stages impose different requirements on the same poisoning content, and each stage operates on the transformed output of its predecessor. Consequently, optimizing one stage may undermine the effectiveness of other stages, while upstream transformations may erase improvements intended for downstream stages. Indirect memory poisoning should therefore be viewed as an end-to-end optimization problem. Based on this insight, we present \textsc{PipePoison}, which collects fine-grained stage feedback from local shadow systems, uses chain-structured losses to identify and optimize the stage bottlenecking end-to-end success, and applies stability-calibrated stage and configuration weights to improve transferability. Across three agent frameworks and four memory mechanisms, \textsc{PipePoison} improves attack utilization rate by 19.1 percentage points. Even on fully unseen victim configurations, it outperforms the strongest baseline by 16 percentage points and remains effective under eight representative defenses.
Problem

Research questions and friction points this paper is trying to address.

long-term memory
indirect memory poisoning
multi-stage pipeline
stage coupling
end-to-end optimization
Innovation

Methods, ideas, or system contributions that make the work stand out.

end-to-end optimization
fine-grained stage feedback
chain-structured losses
stability-calibrated weights
C
Chuanchao Zang
School of Cyber Science and Technology, Shandong University
J
Jianing Wang
School of Cyber Science and Technology, Shandong University
Wenyu Chen
Wenyu Chen
Massachusetts Institute of Technology
optimizationstatistical learning
X
Xiangtao Meng
School of Cyber Science and Technology, Shandong University
L
Li Wang
School of Cyber Science and Technology, Shandong University
Xinyu Gao
Xinyu Gao
NanJing University
Autonomous DrivingMulti-sensor FusionTesting
Z
Zheng Li
School of Cyber Science and Technology, Shandong University; State Key Laboratory of Cryptography and Digital Economy Security, Shandong University; Shandong Key Laboratory of Artificial Intelligence Security, Shandong University
Shanqing Guo
Shanqing Guo
Shandong University