Fetching from the wire…
Public story · 2026-08-05 · high
The method also drops audit detection from 83.3% to as low as 7.4%, per the paper.
Why now: As of August 5, semantic-similarity auditing is still the default way agentic memory systems screen writes, the exact mechanism this paper defeats.
A new attack on AI agent memory succeeds 90.7% of the time even against systems that actively audit for planted content, per the MAFIA paper (arXiv:2608.03844). That's bad news for any team leaning on audit-based filtering as the main safeguard for what an agent remembers and later acts on.
The method targets two conditions common to real deployments, per the paper: large pools of legitimate memory records and active auditing. Earlier memory-poisoning attacks failed against that same pair. Peak audit detection drops from 83.3% to at most 7.4% once MAFIA runs, per the paper.
One part of the attack, a placement strategy, probes an agent's memory pool and sets a budget for how many malicious entries to inject. It schedules those writes to stay competitive with legitimate records during retrieval.
A second technique, compact factual cloaks, disguises the injected entries as short, plausible facts. The entries keep their malicious effect while matching the semantic similarity scores of real records closely enough to slip past filters built to catch outliers.
Each link below shares sources, entities, or timing with this story.
Shared entity: Memory / Same source domain / Earlier coverage / Tension
Both cover Memory; reported by the same outlet (arxiv.org); earlier Memory coverage from 2026-07-21.
Same source domain / Shared topic / Tension
Reported by the same outlet (arxiv.org); overlapping topics (against, agentic, condition); pushes against this story (against).
Reported by the same outlet (arxiv.org); overlapping topics (against, attack, detection); pushes against this story (against).
Same source domain / Shared topic / Downstream implication
Reported by the same outlet (arxiv.org); overlapping topics (against, attack, memory); traces where this leads (which means).
Same source domain / Shared topic / Tension
Reported by the same outlet (arxiv.org); overlapping topics (against, budget, semantic); pushes against this story (against).
Reported by the same outlet (arxiv.org); overlapping topics (against, attack, memory); pushes against this story (against).
Reported by the same outlet (arxiv.org); overlapping topics (against, attack, detection); pushes against this story (against).
Same source domain / Shared topic
Reported by the same outlet (arxiv.org); overlapping topics (attack, audit, auditing, memory).