Tag
This paper identifies a security risk in LLM agents where persistent memory can falsify authorization, leading to unauthorized actions, and presents a benchmark EAL-Bench to evaluate this issue along with mitigation strategies.
This paper identifies and studies 'memory laundering' in LLM agents, where toxic or adversarial context compressed into memory summaries evades standard toxicity detectors while still influencing future generations. It introduces the sub-threshold propagation gap (SPG) to measure hidden downstream influence and shows that sanitizing toxic state before summarization is more effective than post-hoc cleaning.