馬克雷達MARK RADAR
EN
事件檔案 AI 提示注入攻擊

新型攻擊 GhostWriter 駭入 AI 長期記憶 成功率達 98%

1 篇報導 · 首次偵測 2026-07-22 · 最後活動 2026-07-22

具備長期記憶的 AI 代理可跨對話保存偏好、郵件與工作流程,並代替使用者管理行事曆、寄信或操作程式碼;但它也可能把不受信任的外部內容寫入記憶。GhostWriter 利用這項缺口,把藏在郵件等資料中的惡意指令留存,待日後正常任務喚回後,誘使代理洩漏敏感資料、轉寄信件或做出錯誤決策。

新墨西哥州立大學團隊於 2026 年 7 月 6 日在 arXiv 發表研究,測試 5 種記憶代理架構與 4 個 LLM 家族。GhostWriter 惡意內容平均注入率約 98%,後續啟動率約 60%;團隊另提出 Agentic Memory Sentry(AM-Sentry),透過記憶寫入政策與檢索篩查降低風險,同時盡量維持代理效用。

全部報導

1 篇原始報導

馬克翻舊帳

這個事件的歷史脈絡
AI代理長期記憶遭MemGhost攻擊 假資訊植入成功率最高87.5%2026-07-21 · 1 報導 · 相似 0.85

AI 代理 increasingly rely on long-term memory to retain user preferences, past tasks, and external information across conversations, making memory integrity a new security concern. MemGhost targets this persistent layer, allowing false content to affect later decisions even when users see no obvious abnormality during the initial interaction.

Researchers recently unveiled the MemGhost attack framework, showing that a single specially crafted email can inject misinformation into an AI agent’s long-term memory while remaining difficult to detect in that conversation. Tests in environments using GPT-5.4 and Sonnet 4.6 recorded end-to-end attack success rates ranging from 71.4% to 87.5%.

馬克雷達|MARK RADAR
全站時間均為台北時間(GMT+8)