Research
MemSecBench: Poisoned Agent Memories Persist in 84.2% of Cases and Complete the Write-Execute Chain Half the Time
MemSecBench (arXiv 2607.27080, 2026-07-29) traces the same malicious semantics through persistence, downstream consequence, and selective repair across 310 test cases in 48 realistic contexts, under a 24-configuration matrix of 2 agent harnesses × 4 memory backends × 3 LLM backends. Malicious memory persists in 84.2% of cases, the full write-to-execute chain succeeds 50.3% of the time (59.6% among successfully poisoned cases), and selective repair only reaches 56.1%. The spread between configurations is the actionable part: 16.1 points on end-to-end attack success but 41.3 points on repair capability, meaning your memory backend choice matters far more for cleanup than for prevention.
↳ Follow the thread