← all papers · overview

Zombie Agents: Persistent Control Of Self-evolving LLM Agents Via Self-reinforcing Injections

Abstract

Self-evolving LLM agents update their internal state across sessions, often by writing and reusing long-term memory. This design improves performance on long-horizon tasks but creates a security risk: untrusted external content observed during a benign session can be stored as memory and later treated as instruction. We study this risk and formalize a persistent attack we call a Zombie Agent, wher

Related papers

Ranked by semantic similarity — how closely each paper's abstract matches this one (100% = near-identical topic).