The Misattribution Gap: When Memory Poisoning Looks Like Model Failure in Agentic AI Systems
2026-05-25T07:23:32Z•a93e59bc410fe8adb7fb6a6c98cf5222f5ab3559cfb45aa3c6a51ddf5b23db6d
ActInvCKKSCounterfactual Composition TestingFHE overflowIoT testbed BYOT-CPSPoisonForgeSAFESEALactivation inversionagentic AIdata supply-chain poisoningformal verificationguardrailsinstruction tuningmemory poisoningmemory-persistent IFCmisattribution gapperturbation defensesprivacy leakageprompt overflowretrieval-coverage dilemmasemantic norm driftsplit inferencetrust launderingvector storeswatermarking
What happened
This feed contains multiple security-relevant AI research contributions and new attack/defense classes with practical implications for agentic systems, model deployment, and privacy. Key findings: (1) Misattribution Gap / Semantic Norm Drift (SND): memory-layer poisoning of shared vector stores can make agents follow injected policy-like documents across sessions while attribution systems and safety classifiers mislabel the cause as model failure; across 64 documented failures defenders blamed models, four classifiers (including one trained on memory poisoning) produced zero detections across
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- arxiv_cs_cr
- Record identifier
- a93e59bc410fe8adb7fb6a6c98cf5222f5ab3559cfb45aa3c6a51ddf5b23db6d
- Enrichment time
- 2026-05-25T07:23:32Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.