Capability Laundering in Multi-Agent Systems via Memory Poisoning

A research proposal examining how poisoned external content can persist in agent memory and later trigger unauthorized high-privilege actions.

August 8, 2026
# AI Security# Memory Poisoning# Multi-Agent Systems# Prompt Injection
1 /
Loading presentation…

Presentation overview

This presentation introduces a full-chain capability-laundering threat in self-evolving multi-agent systems. It examines how instructions embedded in untrusted external content can be promoted into persistent memory, retrieved in a later session, delegated across agents, and ultimately executed through high-privilege tools.

Research focus

Experimental direction

The proposed OpenClaw-based harness isolates memory, agent roles, access controls, and tool execution so each stage can be measured independently. The deck also positions the work alongside SudoBench, OEP, and Skill-Inject, highlighting persistent memory as the mechanism that transfers attacker-controlled policy across sessions and privilege boundaries.