Defense effectiveness across architectural layers: a mechanistic evaluation of persistent memory attacks on stateful LLM agents
Persistent memory in LLM agents creates an attack surface that production safety classifiers do not observe: the payload enters via RAG retrieval and persists across sessions via tool-mediated memory. We evaluate six defenses across four architectural layers against delayed-trigger attacks on nine open-source models (5,040 runs, N=40 per condition). Five of six defenses fail: input-level filters never see the payload (it enters via RAG, not user input); retrieval-level classifiers observe it but
Record details
Published: 8 May 2026
Source: arXiv
Category: Research
Topics: Military & security · Agents & autonomy
Retrieved: 14 July 2026
Related evidence
These records share source-supplied organisations, an exact publisher byline, automatic topics or regions. The reason is shown on every link; related does not mean supporting, agreeing with or verifying this record.
Agentic AI and the Industrialization of Cyber Offense: Forecast, Consequences, and Defensive Priorities for Enterprises and the Mittelstand
arXiv · 6 May 2026
Pen-Strategist: A Reasoning Framework for Penetration Testing Strategy Formation and Analysis
arXiv · 6 May 2026
GRID: Graph Representation of Intelligence Data for Security Text Knowledge Graph Construction
arXiv · 15 May 2026
AI Agents May Always Fall for Prompt Injections
arXiv · 17 May 2026
Surviving the Unseen: Predictive Defense for Novel Multi-Turn Multimodal Attacks
arXiv · 18 May 2026
Backchaining Loss of Control Mitigations from Mission-Specific Benchmarks in National Security
arXiv · 20 May 2026
How to cite this record
ethics.ai (8 May 2026), “Defense effectiveness across architectural layers: a mechanistic evaluation of persistent memory attacks on stateful LLM agents,” evidence record 4700, https://ethics.ai/record/4700 (originally published by arXiv).
Use and limitations
This page is a stable index and citation surface for a source record. ethics.ai did not author the underlying report and has not independently verified every claim. Automatic topics may be imperfect. For consequential use, quote and cite the original publisher.