TY - JOUR
T1 - Improving Google A2A Protocol: Protecting Sensitive Data and Mitigating Unintended Harms in Multi-Agent Systems
AU - Louck, Yedidel
AU - Stulman, Ariel
AU - Dvir, Amit
N1 - Just Accepted
PY - 2026/6/1
Y1 - 2026/6/1
N2 - Google's A2A protocol provides a secure communication framework for AI agents, but it has critical limitations when handling highly sensitive information such as payment credentials and identity documents. These gaps increase the risk of unintended harms, including unauthorized disclosure, privilege escalation, and misuse of private data in generative multi-agent environments. In this paper, we identify key weaknesses in A2A: insufficient token lifetime control, lack of strong customer authentication, overbroad access scopes, and missing consent flows. We propose a modular, interceptor-based architecture to address these weaknesses. Our refinements introduce a Zero-Trust Interceptor that enforces explicit consent orchestration, ephemeral scoped tokens, and direct user-to-service data channels to minimize exposure across time, context, and topology. A component-level evaluation of the interceptor's deterministic enforcement logic, conducted across 5,000 protocol-enforcement trials, demonstrates that the enhanced protocol structurally eliminates the sensitive-data leakage paths covered by the tested checks, yielding a 0millisecond level. Comparative analysis highlights the advantages of our deterministic, protocol-level enforcement over both the original A2A specification and stochastic model-based safeguards. These contributions establish a practical, statistically validated path for evolving A2A into a privacy-preserving framework for multi-agent systems.
AB - Google's A2A protocol provides a secure communication framework for AI agents, but it has critical limitations when handling highly sensitive information such as payment credentials and identity documents. These gaps increase the risk of unintended harms, including unauthorized disclosure, privilege escalation, and misuse of private data in generative multi-agent environments. In this paper, we identify key weaknesses in A2A: insufficient token lifetime control, lack of strong customer authentication, overbroad access scopes, and missing consent flows. We propose a modular, interceptor-based architecture to address these weaknesses. Our refinements introduce a Zero-Trust Interceptor that enforces explicit consent orchestration, ephemeral scoped tokens, and direct user-to-service data channels to minimize exposure across time, context, and topology. A component-level evaluation of the interceptor's deterministic enforcement logic, conducted across 5,000 protocol-enforcement trials, demonstrates that the enhanced protocol structurally eliminates the sensitive-data leakage paths covered by the tested checks, yielding a 0millisecond level. Comparative analysis highlights the advantages of our deterministic, protocol-level enforcement over both the original A2A specification and stochastic model-based safeguards. These contributions establish a practical, statistically validated path for evolving A2A into a privacy-preserving framework for multi-agent systems.
U2 - 10.1145/3821216
DO - 10.1145/3821216
M3 - ???researchoutput.researchoutputtypes.contributiontojournal.article???
SN - 1049-331X
JO - ACM Transactions on Software Engineering and Methodology
JF - ACM Transactions on Software Engineering and Methodology
ER -