Section 01
Introduction: Spore Attack—A New Threat of Efficient Privacy Extraction Targeting LLM Intelligent Agent Memory
The research team proposes the Spore attack method, which can extract privacy information from the memory of LLM intelligent agents with a single query, bypass existing defense mechanisms, and pose a new security threat to users of personal AI assistants. This attack fills the gap in existing research on contextual privacy risks during the inference phase (especially user interaction information in agent memory) and overcomes limitations of traditional attacks such as high query costs and white-box assumptions.