The Misattribution Gap: When Memory Poisoning Looks Like Model Failure in Agentic AI Systems

2026-05-25T07:23:32Za93e59bc410fe8adb7fb6a6c98cf5222f5ab3559cfb45aa3c6a51ddf5b23db6d
ActInvCKKSCounterfactual Composition TestingFHE overflowIoT testbed BYOT-CPSPoisonForgeSAFESEALactivation inversionagentic AIdata supply-chain poisoningformal verificationguardrailsinstruction tuningmemory poisoningmemory-persistent IFCmisattribution gapperturbation defensesprivacy leakageprompt overflowretrieval-coverage dilemmasemantic norm driftsplit inferencetrust launderingvector storeswatermarking

What happened

This feed contains multiple security-relevant AI research contributions and new attack/defense classes with practical implications for agentic systems, model deployment, and privacy. Key findings: (1) Misattribution Gap / Semantic Norm Drift (SND): memory-layer poisoning of shared vector stores can make agents follow injected policy-like documents across sessions while attribution systems and safety classifiers mislabel the cause as model failure; across 64 documented failures defenders blamed models, four classifiers (including one trained on memory poisoning) produced zero detections across

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
arxiv_cs_cr
Record identifier
a93e59bc410fe8adb7fb6a6c98cf5222f5ab3559cfb45aa3c6a51ddf5b23db6d
Enrichment time
2026-05-25T07:23:32Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.