arXiv:2504.19951cs.CRcs.AI2025-04被引 25

为生成式AI多智能体系统设计防工具劫持的注册安全框架

Securing GenAI Multi-Agent Systems Against Tool Squatting: A Zero Trust Registry-Based Approach

  • 基于零信任架构的集中式工具注册与访问控制
  • 通过动态信任评分和即时凭证降低工具冒用风险
  • 适合关注GenAI系统安全落地的研发与运维人员

生成式AI多智能体系统(MAS)的发展要求标准化协议支持智能体发现并调用外部工具。然而,这些协议也带来了新安全威胁,尤其是工具劫持——即恶意注册或伪装工具。本文分析了在新兴互操作标准(如模型上下文协议MCP)下的工具劫持风险,提出一种全面的工具注册系统。该系统包含管理员控制的注册机制、集中式工具发现、基于专用代理与工具注册服务的细粒度访问策略、基于工具版本与已知漏洞的动态信任评分,以及即时凭证发放。该框架旨在有效防范常见工具劫持攻击,同时保持多智能体系统的灵活性与能力,填补了快速演进的GenAI生态中的关键安全空白,为生产环境中的安全工具集成提供基础。

原文摘要 · Abstract (English)

The rise of generative AI (GenAI) multi-agent systems (MAS) necessitates standardized protocols enabling agents to discover and interact with external tools. However, these protocols introduce new security challenges, particularly; tool squatting; the deceptive registration or representation of tools. This paper analyzes tool squatting threats within the context of emerging interoperability standards, such as Model Context Protocol (MCP) or seamless communication between agents protocols. It introduces a comprehensive Tool Registry system designed to mitigate these risks. We propose a security-focused architecture featuring admin-controlled registration, centralized tool discovery, fine grained access policies enforced via dedicated Agent and Tool Registry services, a dynamic trust scoring mechanism based on tool versioning and known vulnerabilities, and just in time credential provisioning. Based on its design principles, the proposed registry framework aims to effectively prevent common tool squatting vectors while preserving the flexibility and power of multi-agent systems. This work addresses a critical security gap in the rapidly evolving GenAI ecosystem and provides a foundation for secure tool integration in production environments.

GenAI安全多智能体零信任

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。