HIGHOWASP Agentic Top 10 ASI06
Memory and Context Poisoning
Memory and context poisoning attacks target the persistent memory, conversation history, or retrieval context that AI agents rely on for continuity and decision-making, injecting false information that corrupts future interactions. This is particularly dangerous in enterprise settings where agents maintain long-running memory across sessions because poisoned context can influence decisions, alter recommendations, and propagate misinformation long after the initial attack. Evaluate vendors on their support for memory integrity verification, context provenance tracking, anomaly detection in memory updates, and periodic memory sanitization. Effective solutions should distinguish between trusted and untrusted memory sources and provide administrators with tools to audit and correct agent memory state.