A2AS: Agentic AI Runtime Security and Self-Defense

Fuente: arXiv
Gespeichert in:
Bibliographische Detailangaben
Hauptverfasser: Neelou, Eugene, Novikov, Ivan, Moroz, Max, Narayan, Om, Saade, Tiffany, Ayenson, Mika, Kabanov, Ilya, Ozmen, Jen, Lee, Edward, Narajala, Vineeth Sai, Junior, Emmanuel Guilherme, Huang, Ken, Gulsin, Huseyin, Ross, Jason, Vyshegorodtsev, Marat, Travers, Adelin, Habler, Idan, Jadav, Rahul
Format: Preprint
Veröffentlicht: 2025
Schlagworte:
Online-Zugang:
Tags: Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
_version_ 1866911213502332928
author Neelou, Eugene
Novikov, Ivan
Moroz, Max
Narayan, Om
Saade, Tiffany
Ayenson, Mika
Kabanov, Ilya
Ozmen, Jen
Lee, Edward
Narajala, Vineeth Sai
Junior, Emmanuel Guilherme
Huang, Ken
Gulsin, Huseyin
Ross, Jason
Vyshegorodtsev, Marat
Travers, Adelin
Habler, Idan
Jadav, Rahul
author_facet Neelou, Eugene
Novikov, Ivan
Moroz, Max
Narayan, Om
Saade, Tiffany
Ayenson, Mika
Kabanov, Ilya
Ozmen, Jen
Lee, Edward
Narajala, Vineeth Sai
Junior, Emmanuel Guilherme
Huang, Ken
Gulsin, Huseyin
Ross, Jason
Vyshegorodtsev, Marat
Travers, Adelin
Habler, Idan
Jadav, Rahul
contents The A2AS framework is introduced as a security layer for AI agents and LLM-powered applications, similar to how HTTPS secures HTTP. A2AS enforces certified behavior, activates model self-defense, and ensures context window integrity. It defines security boundaries, authenticates prompts, applies security rules and custom policies, and controls agentic behavior, enabling a defense-in-depth strategy. The A2AS framework avoids latency overhead, external dependencies, architectural changes, model retraining, and operational complexity. The BASIC security model is introduced as the A2AS foundation: (B) Behavior certificates enable behavior enforcement, (A) Authenticated prompts enable context window integrity, (S) Security boundaries enable untrusted input isolation, (I) In-context defenses enable secure model reasoning, (C) Codified policies enable application-specific rules. This first paper in the series introduces the BASIC security model and the A2AS framework, exploring their potential toward establishing the A2AS industry standard.
format Preprint
id arxiv_https___arxiv_org_abs_2510_13825
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle A2AS: Agentic AI Runtime Security and Self-Defense
Neelou, Eugene
Novikov, Ivan
Moroz, Max
Narayan, Om
Saade, Tiffany
Ayenson, Mika
Kabanov, Ilya
Ozmen, Jen
Lee, Edward
Narajala, Vineeth Sai
Junior, Emmanuel Guilherme
Huang, Ken
Gulsin, Huseyin
Ross, Jason
Vyshegorodtsev, Marat
Travers, Adelin
Habler, Idan
Jadav, Rahul
Cryptography and Security
Artificial Intelligence
The A2AS framework is introduced as a security layer for AI agents and LLM-powered applications, similar to how HTTPS secures HTTP. A2AS enforces certified behavior, activates model self-defense, and ensures context window integrity. It defines security boundaries, authenticates prompts, applies security rules and custom policies, and controls agentic behavior, enabling a defense-in-depth strategy. The A2AS framework avoids latency overhead, external dependencies, architectural changes, model retraining, and operational complexity. The BASIC security model is introduced as the A2AS foundation: (B) Behavior certificates enable behavior enforcement, (A) Authenticated prompts enable context window integrity, (S) Security boundaries enable untrusted input isolation, (I) In-context defenses enable secure model reasoning, (C) Codified policies enable application-specific rules. This first paper in the series introduces the BASIC security model and the A2AS framework, exploring their potential toward establishing the A2AS industry standard.
title A2AS: Agentic AI Runtime Security and Self-Defense
topic Cryptography and Security
Artificial Intelligence
url https://arxiv.org/abs/2510.13825