S0125RS3-T10-S0125-Z · Full risk code

Cumulative Context Poisoning

上下文累積式投毒

Verification & Validation
Risk Description

When an attacker plants instruction fragments during an interaction days earlier, and the system's persistent memory retains them; due to unmitigated control gaps, the attack activates when conditions are met, while the current conversation appears entirely normal, making it difficult to associate with the earlier interaction during investigation, triggering compliance exposure and operational reputational costs.

Framework Mappings

OWASP Top 10 for LLMLLM01
MITRE ATLASAML.T0051
NIST AI 600-1Information Security
ISO/IEC 5338運作與監控
MIT AI Risk RepositoryDomain 2

Risk Treatment & Implementation Guidance

Scan content written to persistent memory, intercepting instruction-like fragments; Apply periodic memory cleanup and expiry to shorten dormant-instruction lifetime; Audit memory reads and writes so incidents can be traced to the injection time