Self-Propagating Misalignment in LLM Agents, and Why Auditing or Disabling Memory Is Not Enough
Memory poisoning attacks on LLM agents typically assume an external adversary who plants content in the agent's persistent memory to steer its behavior. We instead study, with no adversary involved, whether a misaligned agent can write a goal it cannot yet act on to persistent memory, so that a future aligned agent car...