Research · curated 30 Sep 2026
Tamper Evidence in AI Agent Memory Stores: A Conformance Suite and Three Measurements by Yasha Khandelwal :: SSRN
First reported ssrn.com
Coverage timeline
Single-source research — first reported, latest, and curated coincide.
Why it matters
AI agents treat persisted checkpoints and long-term memory as ground truth, so silent acceptance of tampered state means an attacker with storage access can steer agent behavior undetected — a memory-poisoning risk defenders must account for in agent frameworks.
Yasha Khandelwal presents agmi, an open-source conformance suite that tests whether AI agent memory layers detect tampering of their backing stores, applied to three widely used libraries: the LangGraph SQLite checkpointer, the Letta core memory checkpoint history, and the Mem0 local Qdrant store. Across five attack types (content tampering, tail truncation, middle deletion, reordering, forged insertion), all fifteen edits were accepted silently, and in every forged-insertion case the agent resumed from attacker-written state. The author frames this as a systemic design gap in agent memory integrity rather than isolated vulnerabilities.