Agentic AI governance is a critical component of agentic AI infrastructure ensuring that agents follow their owner's communication and interaction policies, and providing protection against attacks from malicious agents. The state-of-the-art solution, SAGA, assumes a logically centralized point of trust, the Provider, which serves as a repository for user and agent information and actively enforces policies. While SAGA provides protection against malicious agents, it remains vulnerable to a malicious Provider that deviates from the protocol, undermining the security of the identity and access control infrastructure. Deployment on both private and public clouds, each susceptible to insider threats, further increases the risk of Provider compromise. In this work, we analyze the attacks that can be mounted from a compromised Provider, taking into account the different system components and realistic deployments. We identify and execute several concrete attacks with devastating effects: undermining agent attributability, extracting private data, or bypassing access control. We then present three types of solutions for securing the Provider that offer different trade-offs between security and performance. We first present SAGA-BFT, a fully byzantine-resilient architecture that provides the strongest protection, but incurs significant performance degradation, due to the high-cost of byzantine resilient protocols. We then propose SAGA-MON and SAGA-AUD, two novel solutions that leverage lightweight server-side monitoring or client-side auditing to provide protection against most classes of attacks with minimal overhead. Finally, we propose SAGA-HYB, a hybrid architecture that combines byzantine-resilience with monitoring and auditing to trade-off security for performance. We evaluate all the architectures and compare them with SAGA. We discuss which solution is best and under what conditions.
翻译:智能体AI治理是智能体AI基础设施的关键组成部分,确保智能体遵循其所有者的通信与交互策略,并提供针对恶意智能体攻击的防护。现有最先进的解决方案SAGA假设存在逻辑上集中的信任节点——提供方(Provider),该节点作为用户与智能体信息的存储库,并主动执行策略。尽管SAGA能抵御恶意智能体的攻击,但其仍易遭受协议偏离的恶意提供方攻击,从而破坏身份与访问控制基础设施的安全性。在私有云和公有云上的部署均面临内部威胁,进一步增加了提供方被攻破的风险。本研究分析了系统组件和实际部署场景下,从被攻破的提供方可能发起的攻击类型。我们识别并实施了若干具有破坏性后果的具体攻击:破坏智能体可归责性、提取私有数据、或绕过访问控制。随后提出三种在安全性与性能间提供不同权衡的提供方保护方案。首先提出SAGA-BFT,一种提供最强保护的完全拜占庭容错架构,但由于拜占庭容错协议的高成本导致性能显著下降。其次提出SAGA-MON和SAGA-AUD两种创新方案,分别利用轻量级服务端监控或客户端审计,以最小开销抵御大多数攻击类别。最后提出混合架构SAGA-HYB,通过结合拜占庭容错与监控审计技术实现安全性-性能权衡。我们对所有架构进行评估并与SAGA进行对比,讨论不同条件下最优方案的选择。