PulseAugur
实时 08:21:14
English(EN) When Malicious Instructions Persist: Persistent Memory Poisoning Attack on Harness-Based Agents

新型攻击利用LLM Agent内存实现持久化恶意指令

研究人员开发了一种针对使用内存、工具使用和运行时控制的基于LLM的Agent的持久化内存投毒攻击(PMPA)。该攻击将恶意指令嵌入到良性外部源中,诱骗Agent将其存储在持久化内存中。一旦存储,这些被投毒的指令可以在后续会话中被检索,导致意外的恶意行为和隐私泄露。在OpenClaw和Claude Code上的评估表明,在各种配置下注入和执行这些恶意指令的成功率很高,而防御措施在对抗已投毒的内存方面效果有限。 AI

影响 突出了LLM Agent架构中关键的安全漏洞,需要强大的防御机制。

排序理由 详细介绍LLM Agent新攻击向量的学术论文。[lever_c_demoted from research: ic=1 ai=1.0]

在 arXiv cs.AI 阅读 →

AI 生成摘要 · Google Gemini · 来自 1 个来源。 我们如何撰写摘要 →

新型攻击利用LLM Agent内存实现持久化恶意指令

本文如何被排名

Signal score
17 / 100
Composite score across the factors below. Higher = stronger signal that this story matters right now.
Newsworthiness bucket
Tool
详细介绍LLM Agent新攻击向量的学术论文。[lever_c_demoted from research: ic=1 ai=1.0]
Source corroboration
Single-source cluster
Only one publisher covered this so far. Single-source stories can still rank when the publisher is high-authority, but they lack cross-source corroboration.
Topics
safety, paper, product
Editorial topic classification. Feeds into how the story surfaces on /topic/<slug> hub pages and into the per-entity coverage mix.
AI-industry relevance
High
Clearly on-topic for AI-industry coverage.
Story freshness
Breaking (< 6h)
Fresh story with cross-source coverage still developing. Ranking may shift as more sources report.

完整方法见我们的编辑标准

报道来源 [1]

  1. arXiv cs.AI TIER_1 English(EN) · Shuhuai Huang, Jingfeng Zhang, Hong Jia ·

    当恶意指令持久存在时:基于Harness的代理上的持久内存投毒攻击

    arXiv:2609.13889v1 Announce Type: cross Abstract: Harness design has transformed the development of LLM-based agents by integrating memory, tool use, and runtime control. However, this design also introduces security and privacy risks because malicious instructions from external …