发表机构
Northern Arizona University; Majmaah University; Jazan University; Tallinn University of Technology(北亚利桑那大学; 马莱大学; 扎赞大学; 塔林科技大学)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
本文提出A2A-ForensicTrace离线验证层,通过类型化记录和签名收据验证跨组织A2A执行证据,实验显示低延迟且全部验证通过。
AI 中文摘要
与安全相关的智能体到智能体(Agent2Agent, A2A)执行可能跨越组织边界,导致调查人员无法实时访问所有参与系统。离线调查涉及检查保存的记录及其跨记录关系的一致性。本文提出了A2A-ForensicTrace,一个离线验证层,它将运行时观察转换为类型化记录,推导协议相关关系,并将两者提交到事件追踪根下。一个Ed25519签名的收据将根和捕获摘要绑定到事件上下文。评估包括通过官方A2A软件开发工具包(SDK)执行的240次执行,其中动作由大型语言模型(LLM)选择。这些包括120次条件运行和120次匹配对照。所有条件运行返回了预期的有界发现。没有对照产生指示,所有根和收据均验证通过。完整离线验证器的中位内存延迟在场景追踪中为1.61毫秒。在单独的扩展实验中,在1,000个提交叶节点时为30.85毫秒。未来工作将扩大A2A生命周期覆盖范围。
英文摘要
Security-relevant Agent2Agent (A2A) executions can cross organizational boundaries, leaving investigators without live access to all participating systems. Offline investigation involves checking preserved records and their cross-record relationships for consistency. This paper presents A2A-ForensicTrace, an offline verification layer that converts runtime observations into typed records, derives protocol-relevant relationships, and commits both under an incident-trace root. An Ed25519-signed receipt binds the root and capture digest to the incident context. Evaluation comprised 240 executions through the official A2A software development kit (SDK), with actions selected by a large language model (LLM). These included 120 condition runs and 120 matched controls. All condition runs returned the expected bounded findings. No control produced an indication, and all roots and receipts verified. Median in-memory latency of the full offline verifier was 1.61 ms for the scenario traces. In the separate scaling experiment, it was 30.85 ms at 1,000 committed leaves. Future work will broaden A2A lifecycle coverage.
Comments9 pages, 4 figures. Accepted at IEEE IEMCON 2026