AI agents can now remember and hackers can ‘poison’ their memories — a new cybersecurity threat
The important part of memory poisoning is the delay, as a poisoned AI agent may not immediately behave like a compromised system. (Unsplash/Xavier Cee) Artificial intelligence systems are starting to do more than answer questions.
New AI “agents” can remember information from previous interactions, plan a series of steps and use digital tools to complete tasks.
Memory is part of what makes these systems useful.
But my recent research, conducted with my colleague Hadis Karimipour at the University of Calgary, shows that memory can also create a security weakness that is easy to overlook.
Think of an AI agent as an assistant that keeps a notebook of what it learns.
Each time it completes a task, useful information can be written into the notebook and consulted later.
Now imagine that someone manages to slip a misleading instruction into that notebook.
The attacker may not need to take control of the AI directly.
The agent can continue working normally for some time.
But days — or several interactions — later, it may open its notebook, retrieve the poisoned information and treat it as something it previously learned and can trust.
This is known as memory poisoning and the important part is the delay .
A poisoned AI agent may not immediately behave like a compromised system.
An attack that waits Many familiar cybersecurity attacks produce effects relatively quickly.
A malicious link is clicked, malware executes or a stolen password is used to access an account.
5News aggregated this summary from the outlet’s public feed. The full article, with all the context, is on theconversation.com — the content belongs to The Conversation Canada.