pith:CPWBRHAT
ShadowMerge: A Novel Poisoning Attack on Graph-Based Agent Memory via Relation-Channel Conflicts
ShadowMerge poisons graph-based agent memory by injecting relations that share the same query-activated anchor and channel as legitimate evidence.
arxiv:2605.09033 v3 · 2026-05-09 · cs.CR · cs.AI
Add to your LaTeX paper
\usepackage{pith}
\pithnumber{CPWBRHATZL3TN6PA6BA2UNH2FD}
Prints a linked badge after your title and injects PDF metadata. Compiles on arXiv. Learn more · Embed verified badge
Record completeness
Claims
SHADOWMERGE achieves 93.8% average attack success rate, improving the best baseline by 50.3 absolute points, while having negligible impact on unrelated benign tasks.
The graph-memory system will extract, merge into the target anchor neighborhood, and retrieve the poisoned relation for the victim query when it shares the same query-activated anchor and canonicalized relation channel as benign evidence via the AIR pipeline.
ShadowMerge exploits relation-channel conflicts to poison graph-based agent memory, achieving 93.8% average attack success rate on Mem0 and real-world datasets while bypassing existing defenses.
References
Receipt and verification
| First computed | 2026-05-20T00:00:41.867279Z |
|---|---|
| Builder | pith-number-builder-2026-05-17-v1 |
| Signature | Pith Ed25519
(pith-v1-2026-05) · public key |
| Schema | pith-number/v1.0 |
Canonical hash
13ec189c13caf736f9e0f041aa34fa28e16fe313a39df369e6f1e165f678f80e
Aliases
· · · · ·Agent API
Verify this Pith Number yourself
curl -sH 'Accept: application/ld+json' https://pith.science/pith/CPWBRHATZL3TN6PA6BA2UNH2FD \
| jq -c '.canonical_record' \
| python3 -c "import sys,json,hashlib; b=json.dumps(json.loads(sys.stdin.read()), sort_keys=True, separators=(',',':'), ensure_ascii=False).encode(); print(hashlib.sha256(b).hexdigest())"
# expect: 13ec189c13caf736f9e0f041aa34fa28e16fe313a39df369e6f1e165f678f80e
Canonical record JSON
{
"metadata": {
"abstract_canon_sha256": "8a981f444072b094ad1688b6e0bcbe4c6bfae8da37ba84d24ae62a67f8434b2a",
"cross_cats_sorted": [
"cs.AI"
],
"license": "http://arxiv.org/licenses/nonexclusive-distrib/1.0/",
"primary_cat": "cs.CR",
"submitted_at": "2026-05-09T16:16:41Z",
"title_canon_sha256": "99cafecba82d31d45b38b7753fc5ed4b54dc3c30a522023f1bd61277cf64408c"
},
"schema_version": "1.0",
"source": {
"id": "2605.09033",
"kind": "arxiv",
"version": 3
}
}