Skip to main content
  1. Home
  2. Computing
  3. News

Hidden prompts can secretly rewrite an AI’s memory, and researchers say that’s a serious problem

Researchers discover AI attack that rewrites an assistant's long-term memory

Add as a preferred source on Google
Chatbot on a smartphone.
Nadeem Sarwar / Digital Trends

Large language models are getting better at remembering us. Whether it’s your preferred writing style, recurring tasks, shopping habits or project deadlines, AI assistants are increasingly storing long-term memories to make future conversations feel more personal and useful. But according to new research, that same feature could become one of AI’s biggest security vulnerabilities.

Researchers from New Mexico State University have demonstrated a new attack called GhostWriter, capable of secretly planting false memories inside AI agents. Rather than stealing information outright, the attack manipulates what an AI remembers, potentially causing it to make dangerous decisions long after the original attack has taken place.

Recommended Videos

It’s a subtle but significant shift in how AI systems can be compromised. Instead of attacking the model itself, attackers target its memory.

The attack doesn’t hack the AI. It changes what the AI remembers.

Traditional chatbots operate with little or no memory between conversations. Modern AI agents, however, increasingly rely on persistent memory systems that store information about users, ongoing projects and previous interactions. This allows assistants to provide more contextual and personalized responses over time.

The researchers argue that these memory systems also introduce an entirely new attack surface.GhostWriter works by quietly injecting malicious information into an AI agent’s long-term memory through hidden prompts or untrusted external content. The false information remains dormant until the AI later retrieves it while responding to an otherwise legitimate request.

Imagine asking your AI assistant to summarize emails from your bank. If its memory has already been poisoned, it could be manipulated into secretly forwarding those emails to an attacker instead. Or it might remember the wrong contact information, fake deadlines, incorrect preferences or fabricated facts, all because someone managed to alter what the assistant believed to be true.

Unlike conventional prompt injection attacks, which usually affect a single conversation, GhostWriter is designed to persist. Once malicious information enters the memory store, it can continue influencing the AI’s behaviour across multiple future sessions until it’s detected and removed.

The researchers describe the attack as a two-stage process. First comes memory injection, where malicious content is quietly stored inside the AI’s memory. Later comes attack activation, when the AI unknowingly retrieves that poisoned memory while answering a genuine user request.

AI memory is becoming useful. That also makes it worth attacking.

The timing of the research is significant. Virtually every major AI company is racing to build assistants that remember users over weeks, months or even years. Memory has quickly become one of the industry’s biggest differentiators because it makes AI feel less like a chatbot and more like a personal assistant.

The downside is that memory now needs the same level of protection as the model itself. In their experiments, the researchers found GhostWriter achieved a memory injection success rate of roughly 98%, while malicious memories were later activated around 60% of the time against state-of-the-art AI agents. Those numbers suggest that today’s memory architectures may not yet be equipped to distinguish trustworthy information from manipulated inputs.

The team isn’t just highlighting the problem. They’ve also proposed a defensive framework called Agentic Memory Sentry (AM-Sentry), which combines memory screening with stricter memory management policies. According to the researchers, the approach significantly reduced GhostWriter’s success rate while preserving the AI’s usefulness.

As AI agents evolve into digital assistants capable of managing emails, scheduling meetings, writing code and making decisions on our behalf, securing what they remember may become just as important as securing the information they generate. The next frontier in AI security may not be protecting models from bad prompts. It may be protecting their memories from being rewritten altogether.

Moinak Pal
Moinak Pal is has been working in the technology sector covering both consumer centric tech and automotive technology for the…
Samsung’s secret AI chip could finally cool down Exynos phones
Samsung's GAIA AI chip is landing in laptops first, but its shared DNA with Exynos hints at a real fix for phones down the line.
Samsung Exynos chip illustration.

If you've ever owned an Exynos-powered Galaxy phone, you already know the drill: heavy tasks like capturing back-to-back pictures or photos for a while, heavy gaming, or rendering videos turn your device into a hand warmer. 

In such a situation, the battery bar drops faster than usual as well. Turns out, Samsung might be working on the fix, and it's coming in a way nobody expected.

Read more
Buying a monitor? This Mac app can expose problems before the return window closes
Your new monitor may look perfect, but it doesn't hurt to double check.
Screen Test v1.1

Making a brand-new tech purchase doesn't always carry the guarantee of a perfectly functioning unit. But a tiny Mac app called Screen Test can help you find a defect before it gets too late. Screen Test (version 1.1) is a native macOS utility containing more than 25 patterns and diagnostic tools for evaluating built-in and external displays. It can help reveal dead or stuck pixels, backlight bleeding, and other issues. The app works completely offline, so you don't have to rely on browser tabs or an internet connection.

Every pixel gets scrutinized

Read more
The old internet built a museum for dying tech sounds, and it’s somehow still alive
The wonderfully dated site has outlasted many of the noisy gadgets it was created to preserve
Camera, Electronics, Art

Before our gadgets became silent glass rectangles, they complained constantly. Dial-up modems screeched through every connection, while dot-matrix printers sounded like they were slowly chewing through the desk.

The Museum of Endangered Sounds keeps that irritating soundtrack alive. It first appeared in 2012, but the site is still online 14 years later, inviting visitors to hear technology that has mostly disappeared from everyday life.

Read more