{"id":"https://openalex.org/W7161131777","doi":"https://doi.org/10.1109/access.2026.3693560","title":"Temporal Dynamics of Memory Poisoning in Web3-Style LLM Agents","display_name":"Temporal Dynamics of Memory Poisoning in Web3-Style LLM Agents","publication_year":2026,"publication_date":"2026-01-01","ids":{"openalex":"https://openalex.org/W7161131777","doi":"https://doi.org/10.1109/access.2026.3693560"},"language":"en","primary_location":{"id":"doi:10.1109/access.2026.3693560","is_oa":true,"landing_page_url":"https://doi.org/10.1109/access.2026.3693560","pdf_url":null,"source":{"id":"https://openalex.org/S2485537415","display_name":"IEEE Access","issn_l":"2169-3536","issn":["2169-3536"],"is_oa":true,"is_in_doaj":true,"is_core":true,"host_organization":"https://openalex.org/P4310319808","host_organization_name":"Institute of Electrical and Electronics Engineers","host_organization_lineage":["https://openalex.org/P4310319808"],"host_organization_lineage_names":["Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Access","raw_type":"journal-article"},"type":"article","indexed_in":["crossref","doaj"],"open_access":{"is_oa":true,"oa_status":"gold","oa_url":"https://doi.org/10.1109/access.2026.3693560","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5087870144","display_name":"Abbas Yazdinejad","orcid":"https://orcid.org/0000-0002-8669-9777"},"institutions":[{"id":"https://openalex.org/I194028371","display_name":"University of Regina","ror":"https://ror.org/03dzc0485","country_code":"CA","type":"education","lineage":["https://openalex.org/I194028371"]}],"countries":["CA"],"is_corresponding":false,"raw_author_name":"Abbas Yazdinejad","raw_affiliation_strings":["Department of Computer Science, Decentralized Cybersecurity &#x0026; Artificial Intelligence Laboratory (DCAILab), University of Regina, Regina, SK, Canada"],"raw_orcid":"https://orcid.org/0000-0002-8669-9777","affiliations":[{"raw_affiliation_string":"Department of Computer Science, Decentralized Cybersecurity &#x0026; Artificial Intelligence Laboratory (DCAILab), University of Regina, Regina, SK, Canada","institution_ids":["https://openalex.org/I194028371"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5136133835","display_name":"Hadis Karimipour","orcid":"https://orcid.org/0000-0001-7948-4033"},"institutions":[{"id":"https://openalex.org/I168635309","display_name":"University of Calgary","ror":"https://ror.org/03yjb2x39","country_code":"CA","type":"education","lineage":["https://openalex.org/I168635309"]}],"countries":["CA"],"is_corresponding":false,"raw_author_name":"Hadis Karimipour","raw_affiliation_strings":["Department of Electrical and Software Engineering, Smart Cyber-Physical (SCPS) Laboratory, University of Calgary, Calgary, AB, Canada"],"raw_orcid":"https://orcid.org/0000-0001-7948-4033","affiliations":[{"raw_affiliation_string":"Department of Electrical and Software Engineering, Smart Cyber-Physical (SCPS) Laboratory, University of Calgary, Calgary, AB, Canada","institution_ids":["https://openalex.org/I168635309"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":2,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":{"value":1850,"currency":"USD","value_usd":1850},"apc_paid":{"value":1850,"currency":"USD","value_usd":1850},"fwci":0.0,"has_fulltext":false,"cited_by_count":0,"citation_normalized_percentile":{"value":0.76091128,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":null,"biblio":{"volume":"14","issue":null,"first_page":"76200","last_page":"76221"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T12203","display_name":"Mobile Agent-Based Network Management","score":0.13300000131130219,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T12203","display_name":"Mobile Agent-Based Network Management","score":0.13300000131130219,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10126","display_name":"Logic, programming, and type systems","score":0.0689999982714653,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12016","display_name":"Web Data Mining and Analysis","score":0.034699998795986176,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/dynamics","display_name":"Dynamics (music)","score":0.6148999929428101},{"id":"https://openalex.org/keywords/neurophysiology","display_name":"Neurophysiology","score":0.4007999897003174},{"id":"https://openalex.org/keywords/temporal-logic","display_name":"Temporal logic","score":0.24660000205039978},{"id":"https://openalex.org/keywords/acceleration","display_name":"Acceleration","score":0.2328999936580658},{"id":"https://openalex.org/keywords/action","display_name":"Action (physics)","score":0.21389999985694885}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.6258000135421753},{"id":"https://openalex.org/C145912823","wikidata":"https://www.wikidata.org/wiki/Q113558","display_name":"Dynamics (music)","level":2,"score":0.6148999929428101},{"id":"https://openalex.org/C152478114","wikidata":"https://www.wikidata.org/wiki/Q660910","display_name":"Neurophysiology","level":2,"score":0.4007999897003174},{"id":"https://openalex.org/C169760540","wikidata":"https://www.wikidata.org/wiki/Q207011","display_name":"Neuroscience","level":1,"score":0.3944000005722046},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.2879999876022339},{"id":"https://openalex.org/C25016198","wikidata":"https://www.wikidata.org/wiki/Q781833","display_name":"Temporal logic","level":2,"score":0.24660000205039978},{"id":"https://openalex.org/C117896860","wikidata":"https://www.wikidata.org/wiki/Q11376","display_name":"Acceleration","level":2,"score":0.2328999936580658},{"id":"https://openalex.org/C2780791683","wikidata":"https://www.wikidata.org/wiki/Q846785","display_name":"Action (physics)","level":2,"score":0.21389999985694885},{"id":"https://openalex.org/C168451700","wikidata":"https://www.wikidata.org/wiki/Q1306528","display_name":"Neural engineering","level":2,"score":0.20630000531673431},{"id":"https://openalex.org/C50644808","wikidata":"https://www.wikidata.org/wiki/Q192776","display_name":"Artificial neural network","level":2,"score":0.2013999968767166}],"mesh":[],"locations_count":2,"locations":[{"id":"doi:10.1109/access.2026.3693560","is_oa":true,"landing_page_url":"https://doi.org/10.1109/access.2026.3693560","pdf_url":null,"source":{"id":"https://openalex.org/S2485537415","display_name":"IEEE Access","issn_l":"2169-3536","issn":["2169-3536"],"is_oa":true,"is_in_doaj":true,"is_core":true,"host_organization":"https://openalex.org/P4310319808","host_organization_name":"Institute of Electrical and Electronics Engineers","host_organization_lineage":["https://openalex.org/P4310319808"],"host_organization_lineage_names":["Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Access","raw_type":"journal-article"},{"id":"pmh:oai:doaj.org/article:99bf9809dfb042e5a34a20dc9c0d2421","is_oa":true,"landing_page_url":"https://doaj.org/article/99bf9809dfb042e5a34a20dc9c0d2421","pdf_url":null,"source":{"id":"https://openalex.org/S4306401280","display_name":"DOAJ (DOAJ: Directory of Open Access Journals)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by-sa","license_id":"https://openalex.org/licenses/cc-by-sa","version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"IEEE Access, Vol 14, Pp 76200-76221 (2026)","raw_type":"article"}],"best_oa_location":{"id":"doi:10.1109/access.2026.3693560","is_oa":true,"landing_page_url":"https://doi.org/10.1109/access.2026.3693560","pdf_url":null,"source":{"id":"https://openalex.org/S2485537415","display_name":"IEEE Access","issn_l":"2169-3536","issn":["2169-3536"],"is_oa":true,"is_in_doaj":true,"is_core":true,"host_organization":"https://openalex.org/P4310319808","host_organization_name":"Institute of Electrical and Electronics Engineers","host_organization_lineage":["https://openalex.org/P4310319808"],"host_organization_lineage_names":["Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Access","raw_type":"journal-article"},"sustainable_development_goals":[],"awards":[],"funders":[],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":0,"referenced_works":[],"related_works":[],"abstract_inverted_index":{"Memory-enabled":[0],"large":[1],"language":[2],"model":[3],"(LLM)":[4],"agents,":[5],"particularly":[6],"those":[7],"deployed":[8],"in":[9,42,116,211],"long-horizon,":[10],"tool-using":[11],"settings":[12],"such":[13,86],"as":[14],"Web3-style":[15],"autonomous":[16],"workflows,":[17],"introduce":[18],"security":[19],"risks":[20],"that":[21,67,161,183,233],"extend":[22],"beyond":[23],"single-prompt":[24],"injection.":[25],"By":[26],"persisting":[27],"and":[28,34,50,63,142,167,208,223,240],"reusing":[29],"information":[30],"across":[31],"interaction":[32,90,159],"steps":[33,91],"sessions,":[35],"these":[36],"agents":[37],"enable":[38],"memory":[39,114,234],"poisoning":[40,115,222,235],"attacks":[41,87,173,188],"which":[43,172],"adversarial":[44,68],"inputs":[45,77],"modify":[46],"persistent":[47,79,150],"agent":[48,254],"state":[49],"influence":[51],"future":[52],"decisions":[53],"after":[54],"benign":[55,177,192],"intermediate":[56],"interactions.":[57],"Recent":[58],"work":[59],"on":[60],"context":[61,94],"manipulation":[62],"\u201cfake":[64],"memories\u201d":[65],"demonstrates":[66],"content":[69],"can":[70],"be":[71,242],"injected":[72],"into":[73],"an":[74],"agent\u2019s":[75],"prompt-visible":[76],"or":[78,92,200,247],"memory;":[80],"however,":[81],"existing":[82],"evaluations":[83],"largely":[84],"analyze":[85],"at":[88,171,203],"isolated":[89],"static":[93],"snapshots,":[95],"obscuring":[96],"their":[97],"temporal":[98,113,154,239],"dynamics.":[99],"In":[100],"this":[101],"paper,":[102],"we":[103],"present":[104],"the":[105,168],"first":[106],"large-scale,":[107],"trajectory-level":[108],"measurement":[109],"framework":[110],"for":[111,253],"analyzing":[112],"memory-enabled":[117],"LLM":[118],"agents.":[119],"We":[120,152],"construct":[121],"a":[122,184],"schema-constrained":[123],"dataset":[124],"of":[125,187],"2,614":[126],"multi-step":[127,158],"attack":[128,132],"trajectories":[129,160],"spanning":[130],"four":[131],"families,":[133],"<italic":[134,143],"xmlns:mml=\"http://www.w3.org/1998/Math/MathML\"":[135,144],"xmlns:xlink=\"http://www.w3.org/1999/xlink\">chain":[136],"poisoning,":[137],"policy":[138,224],"rewriting,":[139],"backdoor":[140],"triggering</i>,":[141],"xmlns:xlink=\"http://www.w3.org/1999/xlink\">slow":[145],"drift</i>,":[146],"executed":[147],"over":[148,157],"shared":[149],"memory.":[151],"define":[153],"risk":[155,202,228,236],"metrics":[156],"capture":[162],"delayed":[163],"activation,":[164,196],"non-monotonic":[165,227],"escalation,":[166],"earliest":[169],"point":[170],"become":[174],"distinguishable":[175],"from":[176,191],"behavior.":[178],"Our":[179],"empirical":[180],"results":[181],"show":[182],"substantial":[185],"fraction":[186],"remain":[189],"indistinguishable":[190],"behavior":[193],"until":[194,217],"late-stage":[195],"despite":[197],"exhibiting":[198],"low":[199],"medium":[201],"all":[204],"earlier":[205],"steps.":[206],"Slow-drift":[207],"backdoor-trigger":[209],"attacks,":[210],"particular,":[212],"systematically":[213],"evade":[214],"step-local":[215],"evaluation":[216],"terminal":[218],"interactions,":[219],"while":[220],"chain":[221],"rewriting":[225],"exhibit":[226],"trajectories.":[229],"These":[230],"findings":[231],"demonstrate":[232],"is":[237],"inherently":[238],"cannot":[241],"reliably":[243],"assessed":[244],"using":[245],"prompt-level":[246],"step-isolated":[248],"evaluation,":[249],"motivating":[250],"trajectory-aware":[251],"benchmarks":[252],"security.":[255]},"counts_by_year":[],"updated_date":"2026-06-11T09:08:48.828518","created_date":"2026-05-15T00:00:00"}
