Sign In

ShadowMerge: A Novel Poisoning Attack on Graph-Based Agent Memory via Relation-Channel Conflicts

์ž‘์„ฑ์ž
  • Haebom
์นดํ…Œ๊ณ ๋ฆฌ
Empty

์ €์ž

Yang Luo, Zifeng Kang, Tiantian Ji, Xinran Liu, Yong Liu, Shuyu Li, Lingyun Peng

๐Ÿ’ก ๊ฐœ์š”

๋ณธ ๋…ผ๋ฌธ์€ LLM ์—์ด์ „ํŠธ์˜ ๊ตฌ์กฐํ™”๋œ ์žฅ๊ธฐ ๊ธฐ์–ต ๋ฐ ๋‹ค๋‹จ๊ณ„ ์ถ”๋ก ์„ ์ง€์›ํ•˜๋Š” ๊ทธ๋ž˜ํ”„ ๊ธฐ๋ฐ˜ ์—์ด์ „ํŠธ ๋ฉ”๋ชจ๋ฆฌ์— ๋Œ€ํ•œ ์ƒˆ๋กœ์šด ์œ ํ˜•์˜ ์ฃผ์ž… ๊ณต๊ฒฉ์ธ ShadowMerge๋ฅผ ์ œ์•ˆํ•ฉ๋‹ˆ๋‹ค. ShadowMerge๋Š” ์•…์˜์ ์ธ ๊ด€๊ณ„๊ฐ€ ์ •์ƒ์ ์ธ ์ฆ๊ฑฐ์™€ ๋™์ผํ•œ ์ฟผ๋ฆฌ ํ™œ์„ฑํ™” ์•ต์ปค์™€ ๊ด€๊ณ„ ์ฑ„๋„์„ ๊ณต์œ ํ•˜๋ฉด์„œ๋„ ์ƒ์ถฉ๋˜๋Š” ๊ฐ’์„ ๊ฐ–๋„๋ก ํ•˜์—ฌ, ๊ธฐ์กด ๊ณต๊ฒฉ์˜ ํ•œ๊ณ„๋ฅผ ๊ทน๋ณตํ•˜๊ณ  ๋†’์€ ์„ฑ๊ณต๋ฅ ์„ ๋‹ฌ์„ฑํ•ฉ๋‹ˆ๋‹ค.

๐Ÿ”‘ ์‹œ์‚ฌ์  ๋ฐ ํ•œ๊ณ„

โ€ข
๊ทธ๋ž˜ํ”„ ๊ธฐ๋ฐ˜ ์—์ด์ „ํŠธ ๋ฉ”๋ชจ๋ฆฌ์˜ ์ƒˆ๋กœ์šด ๋ณด์•ˆ ์ทจ์•ฝ์ ์„ ๋ฐœ๊ฒฌํ•˜๊ณ , ์ด๋ฅผ ์•…์šฉํ•˜๋Š” ํšจ๊ณผ์ ์ธ ๊ณต๊ฒฉ ๋ฐฉ๋ฒ•๋ก ์„ ์ œ์‹œํ–ˆ์Šต๋‹ˆ๋‹ค.
โ€ข
๊ธฐ์กด์˜ ํ…์ŠคํŠธ ๊ธฐ๋ฐ˜ ์ฃผ์ž… ๊ณต๊ฒฉ์ด ๊ทธ๋ž˜ํ”„ ๊ธฐ๋ฐ˜ ๋ฉ”๋ชจ๋ฆฌ์—์„œ๋Š” ์‹คํŒจํ•˜๋Š” ์ด์œ ๋ฅผ ๋ถ„์„ํ•˜๊ณ , ์ด๋ฅผ ํ•ด๊ฒฐํ•˜๋Š” ์ƒˆ๋กœ์šด ํŒŒ์ดํ”„๋ผ์ธ(AIR)์„ ๊ฐœ๋ฐœํ–ˆ์Šต๋‹ˆ๋‹ค.
โ€ข
์‹คํ—˜์„ ํ†ตํ•ด ShadowMerge๊ฐ€ ๊ธฐ์กด ๊ณต๊ฒฉ ๋Œ€๋น„ ์›”๋“ฑํžˆ ๋†’์€ ์„ฑ๊ณต๋ฅ ์„ ๋ณด์ด๋ฉฐ, ์ •์ƒ์ ์ธ ์ž‘์—…์—๋Š” ๊ฑฐ์˜ ์˜ํ–ฅ์„ ๋ฏธ์น˜์ง€ ์•Š์Œ์„ ์ž…์ฆํ–ˆ์Šต๋‹ˆ๋‹ค.
โ€ข
์ œ์•ˆ๋œ ๊ณต๊ฒฉ์€ ๋Œ€ํ‘œ์ ์ธ ์ž…๋ ฅ๋‹จ ๋ฐฉ์–ด ๊ธฐ๋ฒ•์œผ๋กœ๋„ ํšจ๊ณผ์ ์œผ๋กœ ์™„ํ™”๋˜์ง€ ์•Š์•„, ์ƒˆ๋กœ์šด ๋ฐฉ์–ด ์ „๋žต์˜ ํ•„์š”์„ฑ์„ ์‹œ์‚ฌํ•ฉ๋‹ˆ๋‹ค.
๐Ÿ‘