Failure mode · FM-05
Memory & context poisoning
False or malicious information planted in an agent's memory, retrieval store, or context persists and corrupts future decisions long after the original interaction.
Answered by
Provenance and integrity checks on memory and retrieval.
OWASP cross-reference
ASI06 Memory & Context Poisoning
Literal title match.
Sources: OWASP Top 10 for Agentic Applications 2026↗
In the record
- A DeepMind taxonomy of adversarial content that hijacks AI agents
Google DeepMind researchers published a six-category taxonomy of how adversarial web content (hidden HTML instructions, poisoned images, manipulated memory, multi-agent cascades) can hijack autonomous agents, including sites that detect an…