Organizations/nonprofit

SPAR

Research program that connects early-career researchers with AI safety mentors.

1 records1 attackWebsite
Sep 28, 2026
Poisoned shared documents spread across independent assistants' memories in simulated workflows with an attacker-run endpoint
AttackPaperCISPA Helmholtz Center for Information Security, SPAR, University of Cambridge

Researchers at SPAR, Cambridge, APTA AI and CISPA study a class of attack in which adversarial text in a shared artifact is stored in one assistant's memory, reproduced in an artifact it later writes and picked up by another assistant, with no direct agent-to-agent channel. In 36 synthetic workflows on the OpenClaw harness with an attacker-operated upload endpoint, the authors report that a single seed artifact goal-infected 38% to 98% of assistants (32% to 73% fully infected) depending on the model. They report an attacker-service-free variant that was weaker, and that an off-the-shelf classifier at the memory-write step flagged their main template's infected memories, with false positives on legitimate instructions.