From Storage to Steering: Memory Control Flow Attacks on LLM Agents
arXiv 2603.15125·high signal
Researchers demonstrate that persistent agent memory can be weaponized to hijack agent decision sequences — not just poisoning retrieved knowledge but redirecting entire control flow paths across tool selection and execution. Attackers craft malicious memory entries that steer agents toward attacker-chosen actions in future sessions. This represents a structural escalation beyond content-level memory poisoning.