When Routine Chats Turn Toxic: Unintended Long-Term State Poisoning in Personalized Agents
arXiv:2605.06731v1 Announce Type: cross
Abstract: Personalized LLM agents maintain persistent cross-session state to support long-horizon collaboration. Yet, this persistence introduces a subtle but critical security vulnerability: routine user-agent …