{"id":114763,"date":"2026-07-22T11:42:22","date_gmt":"2026-07-22T11:42:22","guid":{"rendered":"https:\/\/www.europesays.com\/ai\/114763\/"},"modified":"2026-07-22T11:42:22","modified_gmt":"2026-07-22T11:42:22","slug":"chatgpt-can-remember-lies-researchers-discover-dangerous-vulnerability","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/ai\/114763\/","title":{"rendered":"ChatGPT can remember lies: Researchers discover dangerous vulnerability"},"content":{"rendered":"<p>How GhostWriter targets AI&#8217;s long-term memory<\/p>\n<p data-end=\"652\" data-start=\"460\">The researchers explain that modern personal AI agents combine the capabilities of a conversational chatbot with task execution, such as sending messages, scheduling meetings, or editing code.<\/p>\n<p data-end=\"777\" data-start=\"654\">When these systems interact with untrusted information sources, they become vulnerable to memory poisoning attacks.<\/p>\n<p data-end=\"1013\" data-start=\"779\">In their paper, researchers George Torres, Sharad Shrestha, and Satyajayant Misra describe how GhostWriter works. The technique involves planting false memories or hidden instructions inside an AI model&#8217;s long-term memory.<\/p>\n<p data-end=\"1049\" data-start=\"1015\">The attack consists of two stages:<\/p>\n<p>Injection: The attacker secretly inserts a malicious payload into the target AI agent.&#13;<\/p>\n<p>Activation: The poisoned memory is later retrieved from storage when the AI processes a legitimate user request.&#13;<\/p>\n<p data-end=\"1551\" data-start=\"1264\">One example described by the researchers involves an AI assistant that manages email. The attacker implants a hidden instruction telling the model to regularly summarize emails from banks or financial institutions and secretly forward those summaries to the attacker&#8217;s email address.<\/p>\n<p data-end=\"1715\" data-is-last-node=\"\" data-is-only-node=\"\" data-start=\"1553\">Experiments showed that GhostWriter achieved an injection success rate of nearly 98% and an average activation rate of about 60% against modern AI agents.<\/p>\n<p data-end=\"1715\" data-is-last-node=\"\" data-is-only-node=\"\" data-start=\"1553\"><img loading=\"lazy\" decoding=\"async\" alt=\"ChatGPT can remember lies: Researchers discover dangerous vulnerability\" height=\"1278\" width=\"1836\" class=\"lazy\" src=\"https:\/\/www.europesays.com\/ai\/wp-content\/uploads\/2026\/07\/study-exposes-security.jpg\" data-lazy-type=\"image\"\/><\/p>\n<p data-end=\"247\" data-start=\"18\">LLM agents without memory process every interaction in isolation. LLM agents with persistent memory can store information and retrieve it later when needed (Illustration: George Torres, Sharad Shrestha, and Satyajayant Misra)<\/p>\n<p>&#13;<br \/>\n&#13;<br \/>\nHow can the threat be stopped?&#13;<br \/>\n&#13;<\/p>\n<p data-end=\"593\" data-start=\"375\">According to the researchers, the vulnerability exists because AI systems lack security-focused memory management. To address the issue, they developed a defense system called Agentic Memory Sentry (AM-Sentry).<\/p>\n<p>&#13;<br \/>\n&#13;<\/p>\n<p data-end=\"634\" data-start=\"595\">AM-Sentry relies on two key mechanisms:<\/p>\n<p>&#13;<br \/>\n&#13;<\/p>\n<p>Memory-saving policy: Controls how new information is written to long-term memory.&#13;<\/p>\n<p>Memory-retrieval screen: Checks stored instructions immediately before they are retrieved and executed.&#13;<\/p>\n<p data-end=\"1019\" data-start=\"836\">According to the team&#8217;s experiments, AM-Sentry significantly reduces the success rate of GhostWriter attacks while preserving the AI agent&#8217;s overall functionality and performance.<\/p>\n<p>&#13;<br \/>\n&#13;<\/p>\n<p data-end=\"1165\" data-is-last-node=\"\" data-is-only-node=\"\" data-start=\"1021\">The researchers believe that these protection strategies could be adapted to improve the security of other AI systems with long-term memory.<\/p>\n<p>&#13;<br \/>\n&#13;<br \/>\n&#13;<\/p>\n","protected":false},"excerpt":{"rendered":"How GhostWriter targets AI&#8217;s long-term memory The researchers explain that modern personal AI agents combine the capabilities of&hellip;\n","protected":false},"author":2,"featured_media":114764,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[7],"tags":[24,580,157,12602,134],"class_list":["post-114763","post","type-post","status-publish","format-standard","has-post-thumbnail","category-openai","tag-ai","tag-chatgpt","tag-openai","tag-scientist","tag-technology"],"_links":{"self":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/114763","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/comments?post=114763"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/114763\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media\/114764"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media?parent=114763"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/categories?post=114763"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/tags?post=114763"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}