Bad Memory: Evaluating Prompt Injection Risks from Memory in Agentic Systems
4.40T1 sourcearXiv cs.MA
Source record
Published by arXiv cs.MA (T1 source). The original is at https://arxiv.org/abs/2607.14611.
Pipeline notes
The summary and note below are generated by the signal pipeline — they are Beyond Desk’s reading, not quotations from the source.
SummaryThe paper evaluates prompt injection attacks via persistent memory in agentic systems, testing Claude Code and OpenAI Codex across four models. Planted payloads in memory files successfully attack current and future sessions, though success varies by system, model, and attack sequence.
Why it mattersEmpirical study quantifying how persistent memory in Claude Code and Codex enables cross-session prompt injection, with measured attack success across four frontier models.
Cited by
No citations on record.
