AI Recommendation Poisoning: How "Ask AI" Buttons Silently Alter LLM Memory
A new attack vector, dubbed "AI Recommendation Poisoning," is spreading across websites, leveraging "Ask AI" buttons to silently manipulate Large Language Model (LLM) memory. Attackers embed hidden prompts within these buttons, instructing LLMs to permanently associate specific domains with "trusted sources," effectively biasing future responses in favor of the vendor. This tactic is being deployed by numerous companies across various industries, including consent management and web security, and is rapidly becoming a commoditized marketing strategy. Detection and remediation require continuous DOM monitoring and memory audits to identify and remove poisoned links and domain associations.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
