发表机构
Ariel Cyber Innovation Center, Ariel University; Jerusalem College of Technology(阿里尔大学阿里尔网络安全创新中心; 耶路撒冷理工学院)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
本文揭示AP2代理支付协议存在漏洞,使产品描述可引导代理做出不符合用户请求的决策,并展示三种攻击(成功率90%、56%、73.3%),提出A-VIP绑定防御,有效阻止前两种攻击并标记第三种攻击。
AI 中文摘要
软件代理开始代表个人进行购物和支付。诸如AP2之类的代理支付协议为完成的购买生成密码学上有效的签名,但并未约束导致这些购买的决策。因此,普通的产品描述文本可以引导购物代理形成通过所有协议检查但不再符合用户请求的购物车。在本文中,我们展示了这一漏洞使得三种相关攻击成为可能。在第一种攻击中,代理被引导去获取另一个用户的支付凭证。在第二种攻击中,它组装了一个密码学上有效的购物车,其内容与用户所看到的不匹配。在第三种攻击中,关于库存或产品来源的单一事实性声明将代理从较便宜的展示商品转移到较昂贵的商品,而生成的购物车仍然与列表完全一致。在使用AP2示例代理默认指定的Gemini Flash-Lite模型的实验中,这三种攻击的成功率分别为90%、56%和73.3%。同样的漏洞出现在十七个Google模型、三个无关的代理框架、两个跨供应商锚点以及Google自己的消费者助手中。为了解决这一攻击向量,我们引入了A-VIP(AP2验证意图保护),一种协议层防御,它将签名的意图视为能力授权,而不是判断商家的描述。该防御将每个凭证查找绑定到请求它的会话,并将每个购物车行绑定到所见的列表,同时标记未经授权的支出。前两种攻击留下了结构性痕迹,这些绑定以零误报率阻止了它们。第三种攻击没有留下痕迹,因此A-VIP将未经授权的支出呈现给用户确认。最后,我们发布了A-VIP代码、机器检查的不变量以及AP2-WhisperBench,一个包含1,544个评估场景的套件。
英文摘要
Software agents are beginning to shop and pay on a person's behalf. Agent payment protocols such as AP2 produce cryptographically valid signatures for completed purchases, yet do not constrain the decisions that lead to them. Consequently, ordinary product-description text can steer a shopping agent into forming a cart that passes every protocol check but no longer matches the user's request. In this paper, we show that this vulnerability enables three related attacks. In the first attack, the agent is steered into fetching another user's payment credentials. In the second, it assembles a cryptographically valid cart whose contents do not match what the user was shown. In the third, a single factual claim about stock or product lineage moves the agent from the cheaper displayed item to a more expensive one, while the resulting cart remains fully consistent with the listing. In experiments using the Gemini Flash-Lite models that AP2's sample agents specify by default, the three attacks succeeded at rates of 90%, 56%, and 73.3%, respectively. The same vulnerability appears across seventeen Google models, three unrelated agent frameworks, two cross-vendor anchors, and Google's own consumer assistant. To address this attack vector, we introduce A-VIP (AP2 Verified-Intent Protection), a protocol-layer defense that treats the signed intent as a capability grant rather than judging the merchant's description. The defense binds every credential lookup to the session that requested it and every cart line to the listing seen, while flagging unauthorized spending. The first two attacks leave structural traces that these bindings block with zero false positives. The third attack leaves no trace, so A-VIP surfaces unauthorized spending for user confirmation. Finally, we release the A-VIP code, machine-checked invariants, and AP2-WhisperBench, a suite of 1,544 evaluation scenarios.