Agent-interoperability protocols such as A2A and MCP standardize what agents say to one another but assume address-based transport. Whether over HTTP(S) or a content-protecting binding such as MLS-based SLIM, these transports protect message content yet leave the communication graph exposed: which agent contacts which, when, and how often. In agent systems this graph is more consequential than a privacy framing suggests. Endpoints are capability-labeled, workflows are structured and chained, and interactions are coupled to real actions, so an observer recovers more than past relationships: it can infer the pending workflow and, at machine speed, act on that inference before the workflow completes. The threat is therefore one of workflow integrity, not privacy alone. We formalize a threat model for the communication graph and locate what makes its metadata distinctively consequential: not stronger fingerprinting, which we measure to be comparable to other machine traffic, but exposure across independent trust domains, coupled to autonomous action. We define transport- and bootstrap-layer privacy properties, evaluate candidate transports, and give an A2A case study where a metadata-protecting binding surfaces the protocol's implicit identity assumptions. On a generative model anchored to a real capture and over a live A2A binding, a label-blind classifier recovers a task's class from passive metadata well above chance, and from only its opening; a defense-aware adversary does not overturn this, and only the full set of properties drives recovery toward chance. The leverage of acting on the leak is distinct from recoverability: under a fixed budget an adversary realizes most of a clairvoyant attacker's advantage from a workflow's opening, governed by precision over the top-ranked workflows rather than overall accuracy, so a defense suppresses it even while recovery stays above chance.


翻译:诸如A2A和MCP等智能体互操作协议标准化了智能体之间的对话内容,但假定基于地址传输。无论是通过HTTP(S)还是基于MLS的SLIM等内容保护绑定,这些传输虽能保护消息内容,却暴露了通信图:哪个智能体在何时、以何种频率联系了哪个智能体。在智能体系统中,该图的意义超越了隐私框架的范畴。端点带有能力标签,工作流具有结构化与链式特征,交互与真实行动耦合,因此观察者不仅能恢复历史关系,还能推断出待处理的工作流,并以机器速度在工作流完成前就此推断采取行动。因此,威胁涉及工作流完整性,而不仅仅是隐私。我们形式化描述了通信图的威胁模型,并揭示了其元数据具有独特影响的原因:并非更强的指纹识别能力(据我们测量,其与其他机器流量相当),而是在独立信任域间暴露,并耦合自主行动。我们定义了传输层与引导层的隐私属性,评估了候选传输方案,并以A2A案例研究说明:一种保护元数据的绑定会暴露该协议隐含的身份假设。在基于真实捕获的生成模型及实时A2A绑定上,一个忽略标签的分类器能从被动元数据中显著高于随机水平地恢复任务类别,甚至仅凭其初始阶段即可实现;能感知防御的对手无法推翻这一点,只有具备全部属性才能将恢复率降至随机水平。利用泄漏信息采取行动的杠杆效应与可恢复性不同:在固定预算下,对手能从工作流初始阶段获取大部分先知型攻击者的优势,这取决于对排名最高工作流的精确度而非整体准确率;因此防御机制即使恢复到高于随机水平,也能抑制这种杠杆效应。

0
下载
关闭预览

相关内容

元数据(Metadata),又称元数据、中介数据、中继数据[来源请求],为描述数据的数据(data about data),主要是描述数据属性(property)的信息,用来支持如指示存储位置、历史数据、资源查找、文件纪录等功能。元数据算是一种电子式目录,为了达到编制目录的目的,必须在描述并收藏数据的内容或特色,进而达成协助数据检索的目的。
智能体工程(Agent Engineering)
专知会员服务
38+阅读 · 2025年12月31日
基于车路协同的群体智能协同
智能交通技术
10+阅读 · 2019年1月23日
【知识图谱】知识图谱+人工智能=新型网络信息体系
产业智能官
14+阅读 · 2018年11月18日
最新人机对话系统简略综述
专知
26+阅读 · 2018年3月10日
国家自然科学基金
2+阅读 · 2015年12月31日
国家自然科学基金
0+阅读 · 2015年12月31日
国家自然科学基金
5+阅读 · 2015年12月31日
国家自然科学基金
0+阅读 · 2015年12月31日
国家自然科学基金
2+阅读 · 2015年12月31日
国家自然科学基金
0+阅读 · 2015年12月31日
国家自然科学基金
1+阅读 · 2015年12月31日
国家自然科学基金
0+阅读 · 2014年12月31日
国家自然科学基金
18+阅读 · 2009年12月31日
国家自然科学基金
17+阅读 · 2008年12月31日
VIP会员
最新内容
面向2027年及未来的海军情报改革
专知会员服务
2+阅读 · 8月5日
《无人机蜂群:释放人类-蜂群编队的潜能》
专知会员服务
4+阅读 · 8月5日
《战略战术化:一项综合性述评》
专知会员服务
2+阅读 · 8月5日
相关基金
国家自然科学基金
2+阅读 · 2015年12月31日
国家自然科学基金
0+阅读 · 2015年12月31日
国家自然科学基金
5+阅读 · 2015年12月31日
国家自然科学基金
0+阅读 · 2015年12月31日
国家自然科学基金
2+阅读 · 2015年12月31日
国家自然科学基金
0+阅读 · 2015年12月31日
国家自然科学基金
1+阅读 · 2015年12月31日
国家自然科学基金
0+阅读 · 2014年12月31日
国家自然科学基金
18+阅读 · 2009年12月31日
国家自然科学基金
17+阅读 · 2008年12月31日
Top
微信扫码咨询专知VIP会员