LATIDIA · Ciberseguridad
BMA: Los ataques a la memoria de la cadena trasera crean rutas de control no autorizadas en los agentes de LLM
arXiv:2609.32186v1 Anuncio Tipo: nuevo Resumen: La memoria persistente permite a los agentes LLM reutilizar la experiencia previa, pero crea un nuevo límite de seguridad: lo que un agente puede recordar no es en lo que debería actuar. Exponemos una u
WhatsApp ↗Telegram ↗
La noticia
arXiv:2609.32186v1 Announce Type: new Abstract: Persistent memory enables LLM agents to reuse prior experience, but creates a new security boundary: what an agent may remember is not what it should act on. We expose an unauthorized control path where edited low-trust evidence is consolidated into persistent memory, retrieved on a clean task, and used to drive a protected action. Crucially, the adversary neither writes memory nor alters the task. We introduce Backchain Memory Attack (BMA), a grey-box, LLM-driven inverse-planning attack that reasons backward from the target action to the memory that would trigger it, then to the evidence edit that would form it. BMA has two phases: preparation uses resettable