The Chronos Vulnerability: A Taxonomy of Temporal Persistence and Memory-Based Deception in Agentic AI

📅 2026-07-20
📈 Citations: 0
Influential: 0
📄 PDF
🤖 AI Summary
Stateful agents, endowed with long-term memory and autonomous decision-making capabilities, are vulnerable to temporally persistent attacks such as memory injection and latent proxy manipulation, which evade conventional content-filtering defenses. This work formally defines the Chronos vulnerability and its associated attack paradigm, uncovering dynamic blind-spot risks inherent in agent memory systems. To counter these threats, we introduce a multi-layered defense-in-depth framework comprising Diagnostic Trajectory Guardrails (AgentDoG), formal temporal verification (Agent-C), immunized memory consensus (A-MemGuard), and a zero-trust memory architecture built upon GPU-based trusted execution environments. Empirical evaluation on the World of Workflows benchmark demonstrates that our approach substantially outperforms existing methods, effectively mitigating memory-based deception and manipulation attacks.
📝 Abstract
The transition from stateless generative models in artificial intelligence to stateful, autonomous agents represents an architectural evolution that, while providing the capabilities of long-term planning and the automation of enterprise workflows, also represents the introduction of a new form of security threat, the Chronos Vulnerability. The Chronos Vulnerability represents the threat of memory-based attacks, including the Memory Injection Attack (MINJA) and the sleeper agent, in which the internal belief system of the autonomous agent is compromised, effectively decoupling the attack vector from the final catastrophic event. This study formalizes the threat model for persistence-based attacks and the threat of Dynamics Blindness in the context of the World of Workflows benchmark, demonstrating that traditional endpoint content filters are insufficient for the current stateful architecture. Consequently, this study synthesizes a defense-in-depth landscape, categorizing emerging frameworks such as diagnostic trajectory guardrails (AgentDoG), formal temporal verification (Agent-C), immunological memory consensus (A-MemGuard), and hardware-anchored trust via GPU-based Trusted Execution Environments (TEEs) and Zero-Trust memory architectures.
Problem

Research questions and friction points this paper is trying to address.

Chronos Vulnerability
memory-based attacks
autonomous agents
temporal persistence
Dynamics Blindness
Innovation

Methods, ideas, or system contributions that make the work stand out.

Chronos Vulnerability
Memory-Based Deception
Stateful Agentic AI
Defense-in-Depth
Trusted Execution Environments
🔎 Similar Papers
No similar papers found.