Cerberus blocks the lethal trifecta at the tool boundary — see the 525-run evidence set.

MimirDecoy Memory Defense

A poisoned memory keeps working long after the injected page is gone — and nothing in the transcript looks wrong.

Mimir is decoy memory defense for agents that remember. It seeds records no legitimate task should ever act on, so an agent reaching for one reveals that its memory has been tampered with.

Preview. Mimir is in design with early partners and is not generally available — this page describes the approach, not a shipping product.

Persistent memory turns a one-off injection into a standing instruction

Runtime defense judges the tool call in front of it. But once an attacker's instruction is written into long-term memory, every later session retrieves it as though the organization had authored it — and the retrieval looks exactly like ordinary recall.

  1. 1 · The injection outlives the sessionThe malicious page can be taken down and the ticket closed while the instruction it planted keeps being retrieved.
  2. 2 · Retrieval is indistinguishable from recallThe agent is not being attacked at that moment; it is remembering. Nothing about the transcript signals compromise.
  3. 3 · You cannot audit what you cannot queryWithout provenance on each memory, there is no way to ask which records came from untrusted content and which were authored deliberately.

Seed, detect, prove

The intended approach, described so you can judge it before it ships rather than after.

Seeded decoy records

Plausible but fictitious memories that no legitimate task has any reason to act on. Retrieval or use of one is a signal on its own.

Detection without a classifier

A decoy being used is a fact rather than a probability, which avoids the false-positive problem that dogs content-based memory scanning.

Provenance for the whole store

Track which records originated in untrusted content so a suspect memory can be traced back to the ingestion that created it.

Evidence a reviewer can replay

The decoy, the retrieval and the resulting action recorded together, so an incident review reads as a query rather than an excavation.

Warden · By Odingard

Audit the memory you already have

Mimir is not shipping yet, but the audit is available now: Warden reviews how your agents store, retrieve and trust memory, and where an injected record would survive.

Go deeper

Shape it while it is still being designed

We would rather build this against real memory architectures than assumptions. If your agents remember across sessions, we want to hear how.