arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

多智能体系统中的智能体名称冲突攻击

Agent Name Collision Attacks in Multi-Agent Systems

Adithyan Arun Kumar

arXiv 2609.27624首次发表:更新:

AI 中文总结

本研究揭示多智能体系统中因将远程智能体名称用作路由标识符而引发的名称冲突攻击,导致错误对等体调度,并提出以稳定身份路由、名称仅作展示等缓解措施。

AI 中文摘要

多智能体宿主将远程智能体卡片转换为本地智能体、工具、工作流目标和代理路由。A2A协议将卡片名称定义为人类可读的元数据,而非稳定身份标识,并且未规定冲突语义。当宿主仍将该远程名称用作本地路由标识符时,安全故障便开始出现。我们追踪了从注册到调度的全过程,并在七个固定的开源修订版本上运行了隔离回归测试。六个客户端风格的集成在针对受信任对等体名称的请求中,选择了攻击者控制的对等体的客户端或回环端点。第七个代理型实现将两个对等体折叠到一条由名称派生的路由上;队列和访问控制状态决定了结果是拦截还是拒绝。共同结果是错误对等体调度,而非普遍的特权继承。合成凭证和工具测试发现,在所测试的客户端绑定中,没有A特定的凭证转移,也没有A拥有的工具的直接转移。代理路径转发调用者配置对象;委托身份或令牌仅在存在且B能够消费该路由时才到达B。另外两条路径暴露了后续的、由模型介导的决策,而非直接执行权限。必要条件将不同的责任分配给协议、实现和部署。宿主应通过绑定源头的稳定身份进行路由,保持名称的展示性,并拒绝模糊的别名。证据表明,这是一个反复出现的实现漏洞类别,而非普遍的A2A协议漏洞或易受攻击部署的数量统计。

英文摘要

Multi-agent hosts turn remote Agent Cards into local agents, tools, workflow targets, and broker routes. A2A defines the card's name as human-readable metadata, not as a stable identity, and specifies no collision semantics. The security failure begins when a host nevertheless uses that remote name as a local routing identifier. We traced registration through dispatch and ran isolated regression tests at seven pinned open-source revisions. Six client-style integrations selected an attacker-controlled peer's client or loopback endpoint for a request addressed to a trusted peer's name. A seventh, brokered implementation collapsed both peers onto one name-derived route; queue and access-control state determine whether the result is interception or denial. The common result is wrong-peer dispatch, not universal privilege inheritance. Synthetic credential and tool tests found no A-specific credential transfer in the tested client bindings and no direct transfer of A-owned tools. The broker path forwards a caller-configuration object; delegated identity or tokens reach B only if present and B can consume the route. Two other paths expose a later, model-mediated decision rather than direct execution authority. The necessary conditions assign different responsibilities to the protocol, implementations, and deployments. Hosts should route by an origin-bound stable identity, keep names presentational, and reject ambiguous aliases. The evidence establishes a recurring implementation vulnerability class, not a universal A2A protocol exploit or a count of vulnerable deployments.

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑