arXiv:2602.11327cs.CRcs.AI2026-02被引 17

对比分析四种AI代理通信协议的安全部署风险,提出可量化评估框架。

Security Threat Modeling for Emerging AI-Agent Protocols: A Comparative Analysis of MCP, A2A, Agora, and ANP

  • 构建结构化威胁建模分析,识别协议架构与信任假设中的风险点。
  • 提出12类协议级风险评估体系,覆盖创建、运行、更新全生命周期。
  • 以MCP为例量化工具执行错误风险,验证安全假设的可证伪性。

AI代理通信协议(如模型上下文协议MCP、Agent2Agent(A2A)、Agora、代理网络协议ANP)的快速发展正在重塑智能体间及与工具、服务交互的方式。尽管这些协议支持可扩展的多智能体协作与跨组织互操作性,但其安全原则仍缺乏系统研究,尚无协议中心的风险评估框架。本文对四种新兴协议进行系统性安全分析:首先,建立结构化威胁建模方法,考察协议架构、信任假设、交互模式与生命周期行为,识别协议特异性和共有的风险面;其次,提出定性风险评估框架,识别十二类协议级风险,并在创建、运行、更新阶段系统评估其发生概率、影响程度与总体风险水平,为安全部署与未来标准化提供依据;最后,以MCP为例开展数据驱动案例研究,通过量化多服务器组合下缺少强制验证/认证导致的错误提供方工具执行率,将该风险形式化为可证伪的安全声明。结果揭示了设计引发的关键风险面,并为智能体通信生态的安全部署与标准制定提供可操作指导。

原文摘要 · Abstract (English)

The rapid development of the AI agent communication protocols, including the Model Context Protocol (MCP), Agent2Agent (A2A), Agora, and Agent Network Protocol (ANP), is reshaping how AI agents communicate with tools, services, and each other. While these protocols support scalable multi-agent interaction and cross-organizational interoperability, their security principles remain understudied, and standardized threat modeling is limited; no protocol-centric risk assessment framework has been established yet. This paper presents a systematic security analysis of four emerging AI agent communication protocols. First, we develop a structured threat modeling analysis that examines protocol architectures, trust assumptions, interaction patterns, and lifecycle behaviors to identify protocol-specific and cross-protocol risk surfaces. Second, we introduce a qualitative risk assessment framework that identifies twelve protocol-level risks and evaluates security posture across the creation, operation, and update phases through systematic assessment of likelihood, impact, and overall protocol risk, with implications for secure deployment and future standardization. Third, we provide a measurement-driven case study on MCP that formalizes the risk of missing mandatory validation/attestation for executable components as a falsifiable security claim by quantifying wrong-provider tool execution under multi-server composition across representative resolver policies. Collectively, our results highlight key design-induced risk surfaces and provide actionable guidance for secure deployment and future standardization of agent communication ecosystems.

安全建模AI代理协议分析

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。