Glossary · term

Memory and context poisoning

Memory and context poisoning is an attack on runtime information that an AI agent retains, retrieves, or reuses. An adversary causes malicious or misleading content to enter a conversation summary, long-term memory, embedding index, RAG store, cached state, or similar context; that content then influences later reasoning, plans, or tool use. Memory poisoning is the persistent subset. The combined ASI06 label is retained because OWASP and Microsoft use it for both retained context and cross-session state.

Safety2024-07-17Wave 2 · 2024Maturity: 3/5

Origin and context

Research on poisoning agent memory predates the formal ASI06 label. AgentPoison, published at NeurIPS 2024, tested backdoors placed in long-term memory or RAG knowledge bases. MINJA, published at NeurIPS 2025, showed a different threat model in which an attacker attempts to insert malicious records through ordinary query interactions rather than direct database access. OWASP's December 2025 agentic Top 10 then grouped persistent memory and reusable context corruption under ASI06.

Sources: s1, s2, s3

Why it matters

The risk outlives the input that introduced it. A poisoned item may be retrieved in another session or task, presented to the model as trusted history, and affect a later plan or action when the original content is no longer visible. That persistence changes assurance work: reviewing the current prompt alone cannot establish what influenced the agent. Memory writes, retrieval provenance, isolation, version history, rollback, and monitoring become part of the security boundary, although none is a complete defense by itself.

Sources: s1, s3, s4

Example

In the MINJA threat model, an attacker interacts through the agent's normal query interface and tries to induce records that will later be retrieved for a different victim query. AgentPoison instead evaluates malicious demonstrations inserted into memory or a knowledge base and activated through optimized triggers. These are bounded experimental mechanisms, not evidence that every memory-enabled assistant is compromised. A stale but harmless preference stored by mistake is a memory-quality problem, not necessarily an adversarial poisoning attack.

Sources: s2, s3

How it differs

Prompt injection

Prompt injection is the instruction-confusion vulnerability and can affect one interaction. Memory or context poisoning describes corruption that is retained, retrieved, or reused; prompt injection can be its delivery path, but the concepts are not synonyms.

Data poisoning

Data poisoning changes training or fine-tuning inputs so the learned model is altered. Memory and context poisoning targets runtime state or retrievable information without requiring a change to model weights.

Tool poisoning

Tool poisoning places hostile instructions or claims in tool metadata or output. It may feed poisoned context, but its defining attack surface is the tool interface rather than the agent's retained state.

Context rot

Context rot is non-adversarial degradation as context becomes long, distracting, stale, or poorly selected. This entry uses poisoning for deliberate or adversarial corruption, not every case of bad context management.

Maturity and evidence

Maturity is rated 3. Two peer-reviewed conference papers study distinct ways to compromise agent memory, OWASP includes the broader category in its agentic Top 10, and Microsoft documents it in an operational attack catalog. This establishes a cross-organization security category, but not maturity 4: terminology, deployed prevalence, comparative defense evidence, and boundaries around RAG stores and short-lived context are still developing.

Sources: s1, s2, s3, s4

Limits and open questions

Published success rates are specific to particular agents, models, retrievers, attacker access, datasets, and evaluation protocols; they should not be generalized to production prevalence. The combined label is also broader than memory poisoning alone: context may be reused within one workflow without surviving a new session. In informal engineering discussions, context poisoning can describe accidental contamination by stale or irrelevant information. Skills Intelligence scopes this page to the deliberate agent-security risk and states persistence only where the affected state actually persists.

Sources: s1, s2, s3, s4

Related terms

References

Last updated: 2026-09-05

In the Skills Atlas

This term is also covered in the Skills Atlas as agent memory systems skill.

In the Skills Atlas

This term is also covered in the Skills Atlas as prompt injection defense skill.

In the Skills Atlas

This term is also covered in the Skills Atlas as ai data security skill.