2 papers
cs.CR2026
What Guides the Agent? Adjudicating Unauthorized Behavior via Localizing Behavior-Guiding Instructions
Yichao Gao, Yumo Zhang, Yunhao Yao +4
LLM agents integrated with external resources gain complex task capabilities, yet the unified natural-language context channel makes them vulnerable to injection attacks: untrusted…
cs.AI2026
MAFIA: Query-Only Memory Attacks via Probing and Factual Injection against Audited LLM Agents
Jiaming Chen, Yisen Gao, Yanping Li +3
Memory-augmented LLM agents rely on rich context for long-horizon reasoning and acting, yet their memory modules expose a persistent attack surface for malicious records, making th…