A2ABreak:A2A协议的系统性安全分析
A2ABreak: Systematic Security Analysis of the A2A Protocol
浏览论文内容
中文总结 AI 辅助
提出A2ABreak,首个对A2A协议的系统性安全分析框架,通过LLM辅助提取有限状态机并验证,发现11个协议级漏洞,精确率73.3%,F1为84.6%。
中文摘要 AI 辅助
Agent2Agent(A2A)协议现由Linux基金会管理,是一个开放标准,使自主AI智能体能够跨组织边界发现彼此、进行身份验证并委派任务。该协议旨在补充用于工具集成的模型上下文协议(Model Context Protocol, MCP),正迅速成为多智能体生态系统的水平通信层。然而,该协议的安全性尚未得到系统性分析。本文提出了A2ABreak,这是对A2A协议的首次严格系统性安全分析。我们引入了一种新颖框架,利用LLM辅助从自然语言规范中直接提取经过验证的有限状态机,从929条形式化语句中生成包含37个状态和76个转换的统一模型,然后在该模型上进行系统推理,通过对抗性验证在完全合规假设下发现协议级漏洞。我们的分析发现了11个新漏洞,每个漏洞都可被符合规范的对手利用,无需任何实现缺陷。其中发现包括通过未受保护上下文标识符的跨客户端上下文注入、通过委派链中多跳身份丢失的凭证收集,以及通过宣传未经证明能力声明的恶意智能体进行数据外泄。A2ABreak在独立专家评审中达到73.3%的精确率和84.6%的F1分数,而基于相同规范的零样本LLM基线未产生任何确认发现,这表明显式形式化基础对于可靠的协议安全分析至关重要。
英文摘要
The Agent2Agent (A2A) protocol, now governed by the Linux Foundation, is an open standard that enables autonomous AI agents to discover, authenticate with, and delegate tasks to one another across organizational boundaries. Designed to complement the Model Context Protocol (MCP) for tool integration, A2A is rapidly emerging as the horizontal communication layer of the multi-agent ecosystem. Yet the protocol's security has received no systematic analysis. This paper presents A2ABreak, the first rigorous systematic security analysis of the A2A protocol. We introduce a novel framework that utilizes an LLM-assisted extraction of a verified finite-state machine directly from the natural-language specification, producing a unified model of 37 states and 76 transitions from 929 formalized statements, and then systematically reasons over this model to discover protocol-level vulnerabilities through adversarial verification, under a full-compliance assumption. Our analysis uncovers 11 new vulnerabilities, each exploitable by a specification-compliant adversary without requiring any implementation flaw. Among the findings are cross-client context injection through unprotected context identifiers, credential harvesting via multi-hop identity loss in delegation chains, and data exfiltration through rogue agents advertising unattested capability claims. A2ABreak achieves 73.3% precision and 84.6% F1 against independent expert review, while a zero-shot LLM baseline operating over the same specification produces zero confirmed findings, demonstrating that explicit formal grounding is essential for sound protocol security analysis.
发表机构
- Purdue University(普渡大学)
- The University of Texas at Dallas(达拉斯德州大学)
机构由 AI 辅助整理,请以论文原文为准。