Encrypted information can secretly rewrite the AI’s memory, and researchers say that’s a big problem

Examples of large languages are better for remembering. Whether it’s your preferred writing style, repetitive tasks, shopping habits or project deadlines, AI assistants are increasingly storing long-term memories to make future conversations feel more human and helpful. But according to new research, that same feature could be AI’s biggest security vulnerability.
Researchers from New Mexico State University have demonstrated a new attack called GhostWriter, which is able to secretly plant false memories inside AI agents. Instead of stealing information outright, the attack exploits what the AI remembers, potentially causing it to make risky decisions long after the initial attack.
It’s a subtle but important shift in how AI systems can be compromised. Instead of attacking the model itself, attackers target its memory.
Attacking doesn’t wash the AI. It changes what the AI remembers.
Traditional chatbots operate with little or no memory between conversations. Modern AI agents, however, increasingly rely on persistent memory systems that store information about users, ongoing projects and past interactions. This allows assistants to provide more contextual and personalized responses over time.
Researchers argue that these memory systems also present a new area of attack. GhostWriter works by silently injecting malicious information into the long-term memory of an AI agent by using hidden commands or untrusted external content. False information remains inactive until the AI detects it later while responding to a legitimate request.
Imagine asking your AI assistant to summarize emails from your bank. If its memory is already poisoned, it can be used to secretly forward those emails to the attacker instead. Or it may remember wrong contact details, false deadlines, wrong preferences or fabricated facts, all because someone managed to change what the assistant believed to be true.
Unlike typical rapid injection attacks, which usually affect a single conversation, GhostWriter is designed to last. Once malicious information enters the memory store, it can continue to influence the AI’s behavior in all future sessions until it is discovered and removed.
The researchers describe the attack as a two-stage process. First comes memory injection, where malicious content is silently stored in the AI’s memory. Later comes the activation of the attack, where the AI unwittingly discovers that poisoned memory while responding to a real user request.
AI memory is becoming useful. That also makes it worth attacking.
Research time is important. Almost every major AI company is racing to build assistants that remember users within weeks, months or years. Memory has become one of the biggest differentiators in the industry because it makes AI feel less like a chatbot and more like a personal assistant.
The downside is that memory now requires the same level of protection as the model itself. In their tests, the researchers found that GhostWriter achieved a memory injection success rate of about 98%, while malicious memories were later activated about 60% of the time against advanced AI agents. Those numbers suggest that today’s memory structures may not be equipped to reliably separate information from altered input.

The group doesn’t just highlight the problem. They also proposed a protective framework called Agentic Memory Sentry (AM-Sentry), which combines memory inspection with strict memory control policies. According to the researchers, this method significantly reduced the success rate of GhostWriter while maintaining the usefulness of the AI.
As AI agents evolve into digital assistants that can handle emails, schedule meetings, write code and make decisions on our behalf, protecting what they remember may be as important as securing the information they generate. The next frontier in AI security may not protect models from malicious information. It may be to protect their memories from being completely rewritten.



