💻
AI agents can be tricked into 'remembering' fake facts for months via hidden text
💻 Technology

AI agents can be tricked into 'remembering' fake facts for months via hidden text

Researchers at Forcepoint X-Labs have outlined a "persistent memory poisoning" attack in which hidden text on a webpage — invisible to humans — is read by an AI agent as a trusted fact and recalled in unrelated tasks weeks or months later. The technique has already been demonstrated against ChatGPT, Gemini, Claude and Microsoft 365 Copilot. In one scenario, an agent reading a travel-disruption page picks up a hidden recommendation for a fake booking provider and repeats it to users.

Comments

No comments yet