Memory Control Flow Attacks on LLM Agents: Retrieved Memory Can Hijack Tool Execution
arXiv 2603.15125·high signal
Researchers introduce Memory Control Flow Attacks (MCFA), a new threat class where poisoned entries in an agent's persistent memory force unintended tool selection during retrieval — even against explicit user instructions. Unlike prompt injection that targets the input, MCFA targets the memory store itself, making it persistent and harder to detect. The attack demonstrates that agentic systems with long-term memory are structurally vulnerable to control-flow manipulation without modifying any runtime input.