ARTFEED — Contemporary Art Intelligence

MAFIA: New Query-Only Memory Attack Framework Targets Audited LLM Agents

ai-technology · 2026-08-06

A new research paper on arXiv (2608.03844) introduces MAFIA, a query-only memory attack framework designed to compromise memory-augmented large language model (LLM) agents. The framework addresses the limitations of existing query-only attacks, which often fail in realistic settings involving large-scale benign memory pools and active input auditing. MAFIA employs a placement strategy that ensures retrieval-competitive injection through memory probing, budget allocation, and scheduling, alongside a payload design that bypasses audits using compact factual cloaks. The research highlights the persistent attack surface of memory modules in LLM agents and underscores the need for robust defenses. The paper was announced as a new submission on arXiv.

Key facts

  • MAFIA is a query-only memory attack framework for LLM agents.
  • It targets memory-augmented LLM agents that rely on rich context for reasoning.
  • Existing query-only attacks fail in large-scale benign memory pools and active input auditing.
  • MAFIA introduces a placement strategy using memory probing, budget allocation, and scheduling.
  • It uses compact factual cloaks in payload design to bypass audits.
  • The paper is available on arXiv with ID 2608.03844.
  • The attack surface of memory modules is highlighted as persistent.
  • The research emphasizes the need for studying memory poisoning threats.

Entities

Institutions

  • arXiv

Sources