发表机构
Ben-Gurion University of the Negev; Intuit(内盖夫本-古里安大学; Intuit公司)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
本文对谷歌AP2 v0.2开展系统性安全分析,识别出48种威胁及8种高风险威胁,构建测试平台与扫描器,发现授权签名无法保障智能体交易反映用户意图。
AI 中文摘要
谷歌推出的智能体支付协议(Agent Payments Protocol, AP2)支持大型语言模型(LLM)驱动的购物智能体代表用户授权并执行支付操作。其已签名的结账与支付授权(Checkout and Payment Mandates)可在签名后保护交易数据的完整性,但授权前塑造交易的智能体交互及外部输入仍不受该保护,包括智能体间协议(Agent-to-Agent Protocol, A2A)消息和模型上下文协议(Model Context Protocol, MCP)工具调用。此前研究已发现AP2 v0.1存在重放与提示注入攻击,AP2 v0.2虽解决了部分问题,但新增功能与部署假设需重新分析。我们基于AP2 v0.2的角色、交易生命周期、部署架构及信任边界开展系统性安全分析,将生命周期划分为五个阶段,识别出五种部署架构;采用MAESTRO(Multi-Agent Environment, Security, Threat, Risk, Outcome)模型,构建四类威胁智能体、十一个攻击面、十八种攻击者能力及六种攻击者目标,最终形成包含五个攻击家族共48种威胁的目录;使用人工智能漏洞评分系统(Artificial Intelligence Vulnerability Scoring System, AIVSS)对这些威胁评分,确定八种在至少一种架构中达到高风险等级的威胁。因无公开的完整AP2部署,我们构建了覆盖全部五种架构的测试平台,开发了五个概念验证演示,涵盖全部八种高风险威胁及其缓解措施,还开发了感知部署的扫描器,可将适用威胁映射到静态、跨角色一致性及对抗性检查。我们的分析表明,仅有效的授权签名无法确保智能体中介交易在授权前上下文被操纵时反映用户意图。
英文摘要
The Agent Payments Protocol (AP2), introduced by Google, enables large language model (LLM)-driven shopping agents to authorize and execute payments on behalf of users. Its signed Checkout and Payment Mandates protect the integrity of transaction data after signing. Agent interactions and external inputs that shape a transaction before authorization remain outside that protection, including Agent-to-Agent Protocol (A2A) messages and Model Context Protocol (MCP) tool calls. Prior work identified replay and prompt-injection attacks in AP2 v0.1. AP2 v0.2 addresses some of these issues but adds capabilities and deployment assumptions that require renewed analysis. We present a systematic security analysis of AP2 v0.2 based on its roles, transaction lifecycle, deployment architectures, and trust boundaries. We divide the lifecycle into five phases and identify five deployment architectures. Using MAESTRO (Multi-Agent Environment, Security, Threat, Risk, Outcome), we model four threat actors, eleven attack surfaces, eighteen adversary capabilities, and six attacker goals. The resulting catalog contains 48 threats spanning five attack families. We score these threats with the Artificial Intelligence Vulnerability Scoring System (AIVSS), identifying eight that reach the High band in at least one architecture. Because no complete public AP2 deployment was available, we build a testbed spanning all five architectures and develop five proof-of-concept demonstrations covering all eight High-risk threats and their mitigations. We also develop a deployment-aware scanner that maps applicable threats to static, cross-role consistency, and adversarial checks. Our analysis shows that valid mandate signatures alone do not ensure that an agent-mediated transaction reflects the user's intent when its pre-authorization context is manipulated.