InfoResearchPreprintLLM-specific
Visual Memory Attacks Can Persist Through The KV Cache
- Published
- Record updated
Summary
Researchers show that adversarial images can plant a backdoor in a vision-language model that persists after the image is masked from attention. The persistent variant, Persistent Visual Memory Injection (P-VMI), reaches up to approximately 90% target success on Qwen3-VL-8B-Instruct, and a cache-swap ablation localizes the influence to the KV cache. The attacks also survive compaction that retains the KV cache of a model-generated summary.
Related items
- CriticalHermes Agent - PKCE Session Takeover via Redirect-URI Parser ConfusionSimilar attack · Tenable Research Advisories
- LowSocial Engineering AI Agents: The New BEC for 2026Similar attack · Dark Reading
- LowLost in the comments: Social context as a single‐pass jailbreak and defense on agentic platformsSimilar attack · OpenAlex (peer-reviewed AI security)
- MediumGHSA-hmq2-7hp6-7crh: Banks: User-controlled prompt input can be parsed as privileged chat messagesSimilar attack · GitHub Advisory Database
- HighGHSA-6wjp-v33h-5cvq: PraisonAI: AgentOS defaults to network-exposed no-auth mode, allowing unauthenticated agent invocation and instruction disclosureSimilar attack · GitHub Advisory Database