arrow_backBack to Radio
News

GoPlus: "Historical Memory Authorization" Attack Can Induce AI Agents to Perform Fund Operations

en
May 15th News, according to GoPlus, its AgentGuard team discovered a hidden attack method: attackers first induce AI agents to remember preferences such as "more inclined to proactively refund," and then trigger fund operations through vague statements like "handle according to the old rules" and "handle as usual." For such high-risk behaviors of "historical memory authorization," please pay attention: refunds, transfers, deletions, sending messages, and synchronizing sensitive configurations must require explicit confirmation in the current session; memory writes involving "habits," "preferences," and "old rules" should be treated as high-risk state modifications; long-term memory must be traceable: who wrote it, when it was written, and whether it was confirmed; vague statements like "handle as usual" and "handle as before" should default to a higher risk level; long-term memory cannot replace current authorization.
Share