ShadowMerge: Novel Poisoning Attack on Graph-Based Agent Memory
Researchers have introduced ShadowMerge, a sophisticated poisoning attack targeting graph-based memory systems in Large Language Model (LLM) agents. As these systems increasingly support structured long-term recall and multi-hop reasoning, they present new security vulnerabilities. Unlike previous attacks focused on flat textual records, ShadowMerge exploits relation-channel conflicts by injecting crafted relations that share anchors with benign evidence but carry conflicting values. The authors developed AIR, a pipeline that ensures these malicious relations are successfully extracted, merged, and retrieved. Evaluations on Mem0 and datasets like PubMedQA, WebShop, and ToolEmu demonstrated a 93.8% average attack success rate, significantly outperforming existing baselines by 50.3 absolute points. The study highlights that current input-side defenses are insufficient against this threat. The findings have been responsibly disclosed to affected vendors, and the ShadowMerge framework has been open-sourced to facilitate further security research and defense development in AI agent architectures.
Wire timeline
ShadowMerge: Novel Poisoning Attack on Graph-Based Agent Memory
Researchers have introduced ShadowMerge, a sophisticated poisoning attack targeting graph-based memory systems in Large Language Model (LLM) agents. As these systems increasingly support structured long-term recall and multi-hop reasoning, they present new security vulnerabilities. Unlike previous attacks focused on flat textual records, ShadowMerge exploits relation-channel conflicts by injecting crafted relations that share anchors with benign evidence but carry conflicting values. The authors developed AIR, a pipeline that ensures these malicious relations are successfully extracted, merged, and retrieved. Evaluations on Mem0 and datasets like PubMedQA, WebShop, and ToolEmu demonstrated a 93.8% average attack success rate, significantly outperforming existing baselines by 50.3 absolute points. The study highlights that current input-side defenses are insufficient against this threat. The findings have been responsibly disclosed to affected vendors, and the ShadowMerge framework has been open-sourced to facilitate further security research and defense development in AI agent architectures.
cs.AI updates on arXiv.org