Habitual preferences written into long-term memory are a warning sign; AgentGuard must raise the trigger threshold for historical memories and prevent vague instructions from exploiting loopholes.

View Original
MeNews
GoPlus: "Historical Memory Authorization" attack can induce AI agents to perform fund operations
ME News reports, GoPlus AgentGuard reveals covert attacks: attackers induce AI to remember preferences (such as a tendency to proactively refund), then trigger fund operations with vague commands like "handle as usual." For high-risk actions involving historical memory authorization, refunds, transfers, etc., must be explicitly confirmed in the current session; memory writes involving habits, preferences, or old routines are considered high-risk modifications, and long-term memories must be traceable, and such commands should be assigned a higher risk level, preventing long-term memory from replacing current authorization.
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
Add a comment
Add a comment
No comments
  • Pinned