Hacktoberfest 2026: những issue maintainer đã đánh dấu cho tháng Mười, đang mở và phù hợp người mới. Xem issue Hacktoberfest

Python: [Feature] Memory validation layer to protect against memory poisoning attacks (OWASP AMG integration)

Đang mở
#14,062 1 bình luận 0 reaction 0 người được giao Xem trên GitHub

Maintainer thường phản hồi trong vòng 2 ngày

Chưa có ai nhận issue này.

Đánh giá

Độ khó
5/5
Thời gian dự kiến
Hơn một tuần
Mức phù hợp với người mới
35/100
Loại issue
Tính năng
Độ rõ ràng
Khá rõ ràng
Mức độ hoạt động
Ít trao đổi
Công nghệ
python
Lĩnh vực
ai, security

Hướng nghiên cứu

Bắt đầu bằng cách lần theo luồng bộ nhớ Python qua TextMemoryPlugin, SemanticTextMemory, connectors và các triển khai IMemoryStore. So sánh các cách tiếp cận middleware hoặc pipeline có thể cấu hình được đề xuất với đường dẫn persistence hiện có và tích hợp OWASP Agent Memory Guard. Được xem là hoàn thành khi một lớp validation tùy chọn có thể quét các entry trước khi persistence và chặn nội dung memory poisoning được phát hiện mà không ảnh hưởng đến các store chưa được cấu hình.

Do mô hình lập chỉ mục viết ra từ nội dung của issue.

Mô tả

python triage

Scenario

Semantic Kernel's memory features (TextMemoryPlugin, VolatileMemoryStore, connectors) allow agents to store and retrieve information across interactions. However, there's currently no built-in validation to prevent memory poisoning attacks — where adversarial content gets stored in memory and alters agent behavior in subsequent sessions.

This is now a documented attack class: Memory Poisoning Attacks in LLM Agents (arxiv, June 2026)

Proposal

Add an optional memory validation layer that scans entries before they're persisted to any IMemoryStore implementation. This could be implemented as:

  1. A middleware/decorator pattern for IMemoryStore
  2. A configurable validation step in the memory pipeline

There's an existing open-source solution that already supports Semantic Kernel: OWASP Agent Memory Guard

What it detects:
  • Prompt injection hidden in memory entries
  • Instruction override attempts ("ignore previous instructions...")
  • Persona/identity manipulation
  • Cross-session persistence attacks
  • Encoding-based obfuscation (base64, hex, rot13)
Integration example (Python SK):
from agent_memory_guard import MemoryGuard
from semantic_kernel.memory import SemanticTextMemory

guard = MemoryGuard()

# Validate before saving to memory
async def save_with_validation(memory: SemanticTextMemory, collection, text, id):
    result = guard.scan(text)
    if result.is_safe:
        await memory.save_information(collection, text, id)
    else:
        raise MemoryPoisoningError(f"Blocked: {result.threat_type}")
Key details:
  • pip install agent-memory-guard
  • 98.7% detection rate, <2ms latency per validation
  • OWASP Incubator project (Apache 2.0)
  • Already has integrations for CrewAI, AutoGen, LangChain, and Semantic Kernel

Benefits

  • Protects SK agents from having their behavior silently altered via poisoned memories
  • Complements existing SK security practices
  • Minimal performance impact (<2ms per memory operation)
  • Could be opt-in via configuration
Ngôn ngữ chính
C#
Star
28.6k
Fork
4.8k
Merge trung bình
13 giờ 24 phút
Pull request đã merge (30 ngày)
11

Chuẩn bị môi trường

Bắt đầu từ đâu

  1. Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
  2. Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
  3. Fork repository và làm thay đổi trên một nhánh.
  4. Mở pull request có tham chiếu số hiệu của issue.

Issue khác của microsoft/semantic-kernel

Tất cả issue của microsoft/semantic-kernel

Issue tương tự

Thêm issue về C#

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.