Agent-interoperability protocols such as A2A and MCP standardize what agents say to one another but assume address-based transport. Whether over HTTP(S) or a content-protecting binding such as MLS-based SLIM, these transports protect message content yet leave the communication graph exposed: which agent contacts which, when, and how often. In agent systems this graph is more consequential than a privacy framing suggests. Endpoints are capability-labeled, workflows are structured and chained, and interactions are coupled to real actions, so an observer recovers more than past relationships: it can infer the pending workflow and, at machine speed, act on that inference before the workflow completes. The threat is therefore one of workflow integrity, not privacy alone. We formalize a threat model for the communication graph and locate what makes its metadata distinctively consequential: not stronger fingerprinting, which we measure to be comparable to other machine traffic, but exposure across independent trust domains, coupled to autonomous action. We define transport- and bootstrap-layer privacy properties, evaluate candidate transports, and give an A2A case study where a metadata-protecting binding surfaces the protocol's implicit identity assumptions. On a generative model anchored to a real capture and over a live A2A binding, a label-blind classifier recovers a task's class from passive metadata well above chance, and from only its opening; a defense-aware adversary does not overturn this, and only the full set of properties drives recovery toward chance. The leverage of acting on the leak is distinct from recoverability: under a fixed budget an adversary realizes most of a clairvoyant attacker's advantage from a workflow's opening, governed by precision over the top-ranked workflows rather than overall accuracy, so a defense suppresses it even while recovery stays above chance.
翻译:诸如A2A和MCP等智能体互操作协议标准化了智能体之间的对话内容,但假定基于地址传输。无论是通过HTTP(S)还是基于MLS的SLIM等内容保护绑定,这些传输虽能保护消息内容,却暴露了通信图:哪个智能体在何时、以何种频率联系了哪个智能体。在智能体系统中,该图的意义超越了隐私框架的范畴。端点带有能力标签,工作流具有结构化与链式特征,交互与真实行动耦合,因此观察者不仅能恢复历史关系,还能推断出待处理的工作流,并以机器速度在工作流完成前就此推断采取行动。因此,威胁涉及工作流完整性,而不仅仅是隐私。我们形式化描述了通信图的威胁模型,并揭示了其元数据具有独特影响的原因:并非更强的指纹识别能力(据我们测量,其与其他机器流量相当),而是在独立信任域间暴露,并耦合自主行动。我们定义了传输层与引导层的隐私属性,评估了候选传输方案,并以A2A案例研究说明:一种保护元数据的绑定会暴露该协议隐含的身份假设。在基于真实捕获的生成模型及实时A2A绑定上,一个忽略标签的分类器能从被动元数据中显著高于随机水平地恢复任务类别,甚至仅凭其初始阶段即可实现;能感知防御的对手无法推翻这一点,只有具备全部属性才能将恢复率降至随机水平。利用泄漏信息采取行动的杠杆效应与可恢复性不同:在固定预算下,对手能从工作流初始阶段获取大部分先知型攻击者的优势,这取决于对排名最高工作流的精确度而非整体准确率;因此防御机制即使恢复到高于随机水平,也能抑制这种杠杆效应。