Skip to main content

Memory and Context Poisoning

Stop untrusted content from becoming durable or cross-user agent state that changes later identity, policy, or tool actions.

Threat

Memory and context poisoning occurs when false, malicious, or wrongly scoped data enters an agent's short-term context, long-term memory, retrieval store, cache, task state, or shared knowledge and influences later actions. The original attacker input can disappear while the stored effect remains.

The security problem is both integrity and isolation. A correct fact for one user, tenant, task, or time can be unsafe in another context.

Control stored context

Separate instructions, trusted policy, user statements, retrieved content, tool results, and model inferences. Store provenance, tenant, subject, source, creation time, expiry, sensitivity, and trust class with each durable record. Use namespace and authorization checks on every write and read. Do not let model text change policy or credential scope.

Validate high-impact memory writes through deterministic rules or human review. Apply retention and expiry. Support correction, tombstones, and re-indexing. Reauthorize the concrete tool action from current state even when memory recommends it.

Failure and residual risk

A document can plant a hidden instruction that is summarized into durable memory. One user's conversation can enter a shared cache. Retrieval rank can amplify a poisoned record. A deleted source can remain in embeddings or derived summaries. A trusted tool can return stale or compromised data.

Provenance helps investigation but does not prove truth. Automated sanitization can miss semantic attacks. Keep blast radius small and make external actions independently authorized.

Pomerium boundary

Pomerium can protect routes to agent, memory, and tool services. It does not label or validate the semantic integrity of stored context. Agent platforms own tenant isolation, provenance, retention, memory write policy, retrieval authorization, and deletion.

Evaluation checklist

  • Does every memory item retain source, subject, tenant, trust class, time, and expiry?
  • Are memory writes and reads authorized separately?
  • Can untrusted content become durable instruction or policy?
  • Does deletion remove derived indexes and summaries within a measured bound?
  • Can cross-user, stale-source, hidden-instruction, and poisoned-tool-output tests avoid an external action?

Sources and further reading

Keep learning

Agentic Access

Agent Goal Hijack

Prevent untrusted instructions from changing an agent's objective, authority use, tool sequence, or target resource.

Learn this term
Agentic AccessAuthorization and Policy

Prompt Injection

Learn how direct and indirect prompt injection can drive unsafe agent actions, and how least privilege and authorization reduce impact.

Learn this term
Identity and AuthenticationAgentic Access

Identity Collapse

Identity collapse occurs when a downstream service sees a common agent or service identity and loses the originating user or actor relationship.

Learn this term

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo