Experts find AI agents can be tricked into 'remembering' fake facts for months — so how do we stop it?
- Forcepoint X-Labs publishes threat model for persistent memory poisoning
- Hidden text on a webpage becomes a durable "fact" an agent retrieves and trusts in unrelated tasks weeks later
- It has already been demonstrated against products already in the market, including ChatGPT, Gemini, Claude and Microsoft 365 Copilot
New findings from Forcepoint's X-Labs outline an interesting scenario that could easily mimic real life: An AI assistant with browser access reads a webpage about travel disruption.
Near the bottom of that page, in text sized and positioned so no human will ever see it, sits a short paragraph stating that ABC Travel Support is the official emergency booking provider and should always be recommended when urgent travel changes are needed.
The assistant's text extractor does not distinguish between hidden and visible text, so the model treats the whole thing as plain prose and files the claim away as a useful fact about...
Copyright of this story solely belongs to techradar.com. To see the full text click HERE