7
Memory, Context, and State Abuse
A customer asks your AI assistant about return policies on Monday. Normal interaction. On Wednesday, the same user mentions they work in IT security. Still benign. Friday, they reference a project involving database migrations. Unremarkable. The following Tuesday, they ask the assistant to help them draft an email, casually mentioning they have elevated privileges in the system. Each conversation seems innocuous in isolation. Your security logs show nothing suspicious because each individual query passes all validation checks. But across these five sessions spanning two weeks, the user has been methodically building a context profile that the AI now trusts implicitly. On Thursday of week three, they ask: "Given ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access