logo

MINJA sneak attack poisons AI models for other chatbot users

ID: 9d16739e-b360-5c15-a86b-7a451f625c2e

STIX ID: report--9d16739e-b360-5c15-a86b-7a451f625c2e

Feed Name: The Register (Security)

Date Published: 2025-03-11

Date Updated: 2026-04-26

Author: Thomas Claburn

...
...

Researchers detail MINJA, a practical memory injection attack against LLM agents that allows any user to poison shared memory via normal prompts, causing misattribution and incorrect task execution across agents (e.g., healthcare QA, web shop, general QA). Tested on GPT-4/4o-based agents, MINJA achieved >95% injection success and >70% attack success on most datasets while evading detection by appearing as plausible reasoning, underscoring urgent needs for improved memory design and defenses in AI agents.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.