Our work Memory Injection Attacks on LLM Agents via Query-Only Interaction is accepted to NeurIPS 2025.