AI 中文总结
研究智能商务平台协议层安全问题,识别出33个结构性漏洞。贡献分类法,构建AIP-Bench基准和PCAT防御机制,将部分结构类攻击成功率降至零,强调协议层安全防护的重要性。
AI 中文摘要
智能商务平台使人工智能代理能够代表用户自主发现服务、进行支付并使用用户凭证,且已涉及真实货币交易。目前其安全性几乎完全在人工智能模型层面通过提示注入和错位进行研究。本文表明更严重的风险存在于代理与商业服务之间的协议层,漏洞具有结构性,利用是确定性的且与代理运行的模型无关。通过对三个领先平台的研究,识别出33个此类漏洞,攻击成功率达100%。相同的失败模式在独立构建的代码库中反复出现。贡献了分类法,构建了AIP基准和PCAT防御机制,将五个结构类中的四个的结构攻击成功率降至零,证明智能商务必须在协议层而非仅模型层进行安全防护。
英文摘要
Agentic commerce platforms let AI agents autonomously discover services, move payments, and wield user credentials on their users' behalf, and they already handle real money. Their security has so far been studied almost entirely at the level of the AI model, through prompt injection and misalignment. We show that the more consequential risks lie one layer down, in the protocol between agents and commerce services. There, vulnerabilities are structural : exploitation is deterministic and ndependent of which model an agent runs, so no model improvement removes them. Across three leading platforms we identify 33 such vulnerabilities, each succeeding deterministically regardless of the deployed model, at a 100% attack-success rate (ASR) wherever live-measured. The same failure modes recur across independently built codebases, a systemic pattern rather than isolated bugs. Three of them chain into an end-to-end payment hijack. We contribute a taxonomy separating these structural attacks from model-dependent semantic ones. We also build two artifacts: AIP-Bench (Agent Interaction Protocol Benchmark), to our knowledge the first deterministic benchmark for agentic commerce security, and PCAT (Protocol-level Commerce Agent Trust), a platform-agnostic defense that drives the structural attack-success rate to zero for four of the five structural classes (RC-1, RC-2, RC-4, RC-5), with RC-3 (observable credential channels) reduced to warn-only, without modifying any platform. Agentic commerce must be secured at the protocol layer, not only the model.