Skip to content

Author

Chuan-Chao Zang

We have 5 of 6 papers

We haven’t gathered this author’s papers yet. Follow them and we’ll fetch their work.

Not the right person? Other researchers publish under this name.

Preprint Sep 2026

Transferable End-to-End Optimization for Indirect Long-Term Memory Poisoning in LLM Agents

Long-term memory can turn untrusted external content into persistent influence over an LLM agent's future decisions, creating the threat of indirect memory poisoning. A successful attack must survive a multi-stage pipeline comprising memory writing, retrieval, and utilization. Existing attacks largely rely on intra-sta...

Chuan-Chao Zang, Jianing Wang, Wenyu Chen et al. · 0 citations
#artificial intelligence Preprint Aug 2026

Understanding and Exploiting Initialization Anchoring Weakness in Feedback-Based Agent Planning

It is shown that feedback-based agents can retain early biases even when later correction is available, and a black-box framework for exploiting this weakness is proposed that operationalizes the three factors as directional-shift, contextual-plausibility, and counterevidence-resilience signals under either limited tar...

Chuan-Chao Zang, Jia-Ning Wang, Wen-Yu Chen et al. · 0 citations
Preprint Aug 2026

Extracting Knowledge from Tools in LLM Agents

This paper proposes ToolSiphon, a query-only extraction attack that introduces two complementary signals: a target-discriminative signal, implemented through Tool Contrastive Analysis, to steer queries toward the target tool; and a response-grounded factual signal, implemented through Evidence Chained Feedback, to miti...

Chuan-Chao Zang, Jia-Ning Wang, Wen-Yu Chen et al. · 0 citations
Preprint Aug 2026

Understanding Stage-Wise Utility-Risk Trade-offs in LLM Agent Memory

Control evaluations reveal that targeted poisoning risk varies across memory operations and motivate stage-aware evaluation and control of LLM-agent memory, showing that targeted poisoning risk varies across memory operations.

Chuan-Chao Zang, Zi-Jian Cao, Xiang-Tao Meng et al. · 0 citations
Jul 2026

Isolated but Exposed: Persistence-Based Memory Extraction Attack on LLM Agents

The first extraction attack designed for this threat model, SPORE decouples the adversarial command from retrieval anchors by persisting the command in short-term memory and emitting semantically pure anchors in tool responses, demonstrating that memory isolation alone is insufficient and call for reexamining tool-side...

Xinyu Gao, Wenyu Chen, Xiangtao Meng et al. · 1 citation

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.