Memory and context poisoning
Memory and context poisoning is an attack on runtime information that an AI agent retains, retrieves, or reuses. An adversary causes malicious or misleading content to enter a conversation summary, long-term memory, embedding index, RAG store, cached state, or similar context; that content then influences later reasoning, plans, or tool use. Memory poisoning is the persistent subset. The combined ASI06 label is retained because OWASP and Microsoft use it for both retained context and cross-session state.
Origin and context
Research on poisoning agent memory predates the formal ASI06 label. AgentPoison, published at NeurIPS 2024, tested backdoors placed in long-term memory or RAG knowledge bases. MINJA, published at NeurIPS 2025, showed a different threat model in which an attacker attempts to insert malicious records through ordinary query interactions rather than direct database access. OWASP's December 2025 agentic Top 10 then grouped persistent memory and reusable context corruption under ASI06.
Why it matters
The risk outlives the input that introduced it. A poisoned item may be retrieved in another session or task, presented to the model as trusted history, and affect a later plan or action when the original content is no longer visible. That persistence changes assurance work: reviewing the current prompt alone cannot establish what influenced the agent. Memory writes, retrieval provenance, isolation, version history, rollback, and monitoring become part of the security boundary, although none is a complete defense by itself.
Example
In the MINJA threat model, an attacker interacts through the agent's normal query interface and tries to induce records that will later be retrieved for a different victim query. AgentPoison instead evaluates malicious demonstrations inserted into memory or a knowledge base and activated through optimized triggers. These are bounded experimental mechanisms, not evidence that every memory-enabled assistant is compromised. A stale but harmless preference stored by mistake is a memory-quality problem, not necessarily an adversarial poisoning attack.
How it differs
Prompt injection
Prompt injection is the instruction-confusion vulnerability and can affect one interaction. Memory or context poisoning describes corruption that is retained, retrieved, or reused; prompt injection can be its delivery path, but the concepts are not synonyms.
Data poisoning
Data poisoning changes training or fine-tuning inputs so the learned model is altered. Memory and context poisoning targets runtime state or retrievable information without requiring a change to model weights.
Tool poisoning
Tool poisoning places hostile instructions or claims in tool metadata or output. It may feed poisoned context, but its defining attack surface is the tool interface rather than the agent's retained state.
Context rot
Context rot is non-adversarial degradation as context becomes long, distracting, stale, or poorly selected. This entry uses poisoning for deliberate or adversarial corruption, not every case of bad context management.
Maturity and evidence
Maturity is rated 3. Two peer-reviewed conference papers study distinct ways to compromise agent memory, OWASP includes the broader category in its agentic Top 10, and Microsoft documents it in an operational attack catalog. This establishes a cross-organization security category, but not maturity 4: terminology, deployed prevalence, comparative defense evidence, and boundaries around RAG stores and short-lived context are still developing.
Limits and open questions
Published success rates are specific to particular agents, models, retrievers, attacker access, datasets, and evaluation protocols; they should not be generalized to production prevalence. The combined label is also broader than memory poisoning alone: context may be reused within one workflow without surviving a new session. In informal engineering discussions, context poisoning can describe accidental contamination by stale or irrelevant information. Skills Intelligence scopes this page to the deliberate agent-security risk and states persistence only where the affected state actually persists.
Related terms
References
- OWASP Top 10 for Agentic Applications 2026 — ASI06: Memory & Context PoisoningOWASP GenAI Security Project · 2025-12-09 · class A
- AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge BasesChen et al. / NeurIPS 2024 · 2024-07-17 · class A
- Memory Injection Attacks on LLM Agents via Query-Only InteractionDong et al. / NeurIPS 2025 · 2025 · class A
- AI Memory / Context Poisoning (Corruption)Microsoft Learn · 2026-08-01 · class A
Last updated: 2026-09-05
This term is also covered in the Skills Atlas as agent memory systems skill.
This term is also covered in the Skills Atlas as prompt injection defense skill.
This term is also covered in the Skills Atlas as ai data security skill.