MEGA Hub

MAFIA: Query-Only Memory Attacks via Probing and Factual Injection against Audited LLM Agents

Authors

Do you know Jiaming Chen?You can claim authorship or link another user.Do you know Yisen Gao?You can claim authorship or link another user.Do you know Yanping Li?You can claim authorship or link another user.Do you know Zifan Liu?You can claim authorship or link another user.Do you know Yumeng Zhang?You can claim authorship or link another user.Do you know Jun Zhang?You can claim authorship or link another user.

Abstract

Memory-augmented LLM agents rely on rich context for long-horizon reasoning and acting, yet their memory modules expose a persistent attack surface for malicious records, making the study of memory poisoning threats imperative. However, existing query-only attacks often fail to remain effective in two realistic and prevalent settings: large-scale benign memory pools and active input auditing. Consequently, current approaches fall short when facing the dual challenges of high retrieval competitiveness and rigorous semantic checks. To overcome these limitations, we propose MAFIA, a query-only Memory Attack framework via probing and Factual Injection against Audit, tailored to this extended threat model. Specifically, MAFIA introduces: (1) a placement strategy that ensures retrieval-competitive injection via memory probing, budget allocation, and scheduling; and (2) a payload design that bypasses audits using compact factual cloaks, preserving malicious effects while maintaining high semantic similarity. Extensive evaluations reveal that MAFIA achieves up to a 90.7% attack success rate while suppressing audit detection from a peak of 83.3% to at most 7.4%, exposing critical vulnerabilities across agentic memory systems. Code will be made publicly available at https://github.com/JiamingChen1234/MAFIA.

Community

00

Publication notes

Author note
17 pages, 5 figures