דילוג לניווט ראשי דילוג לחיפוש דילוג לתוכן הראשי

Security Analysis of Agentic AI Communication Protocols: A Comparative Evaluation

פרסום מחקרי: פרסום בכתב עתמאמרביקורת עמיתים

תקציר

Multi-agent systems (MAS) powered by artificial intelligence (AI) are increasingly foundational to complex, distributed workflows. Yet, the security of their underlying communication protocols remains critically under-examined. This paper presents the first empirical, comparative security analysis of three leading communication standards: Google’s Agent-to-Agent (A2A) protocol, the SDK-based Agent Communication Protocol (ACP), and the blockchain-integrated CORAL protocol. Using a 14 point vulnerability taxonomy, we systematically assess their defenses across authentication, authorization, integrity, confidentiality, and availability. Our results reveal a pronounced security dichotomy: CORAL exhibits a robust architectural design, particularly in its transport-layer message validation and session isolation, but suffers from critical implementation-level vulnerabilities, including authentication and authorization failures at its SSE gateway. Conversely, ACP’s architectural flexibility, most notably its optional JWS enforcement, translates into high-impact integrity and confidentiality flaws. We contextualize these findings within current industry trends, highlighting that existing protocols remain insufficiently secure. Finally, we propose the Secure Transport Envelope (STE), a formalized hybrid architecture that combines CORAL’s transport locking with ACP’s cryptographic integrity, offering a concrete blueprint for the next generation of secure agent communication.
שפה מקורית???core.languages.und???
כתב עתACM Transactions on AI Security and Privacy
מזהי עצם דיגיטלי (DOIs)
סטטוס פרסוםפורסם - 1 מרץ 2026

פורמט ציטוט ביבליוגרפי