Security Considerations for Artificial Intelligence Agents

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Li, Ninghui, Zhang, Kaiyuan, Polley, Kyle, Ma, Jerry
Format: Preprint
Published: 2026
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866918429553852416
author Li, Ninghui
Zhang, Kaiyuan
Polley, Kyle
Ma, Jerry
author_facet Li, Ninghui
Zhang, Kaiyuan
Polley, Kyle
Ma, Jerry
contents This article, a lightly adapted version of Perplexity's response to NIST/CAISI Request for Information 2025-0035, details our observations and recommendations concerning the security of frontier AI agents. These insights are informed by Perplexity's experience operating general-purpose agentic systems used by millions of users and thousands of enterprises in both controlled and open-world environments. Agent architectures change core assumptions around code-data separation, authority boundaries, and execution predictability, creating new confidentiality, integrity, and availability failure modes. We map principal attack surfaces across tools, connectors, hosting boundaries, and multi-agent coordination, with particular emphasis on indirect prompt injection, confused-deputy behavior, and cascading failures in long-running workflows. We then assess current defenses as a layered stack: input-level and model-level mitigations, sandboxed execution, and deterministic policy enforcement for high-consequence actions. Finally, we identify standards and research gaps, including adaptive security benchmarks, policy models for delegation and privilege control, and guidance for secure multi-agent system design aligned with NIST risk management principles.
format Preprint
id arxiv_https___arxiv_org_abs_2603_12230
institution arXiv
publishDate 2026
record_format arxiv
spellingShingle Security Considerations for Artificial Intelligence Agents
Li, Ninghui
Zhang, Kaiyuan
Polley, Kyle
Ma, Jerry
Machine Learning
Artificial Intelligence
Cryptography and Security
This article, a lightly adapted version of Perplexity's response to NIST/CAISI Request for Information 2025-0035, details our observations and recommendations concerning the security of frontier AI agents. These insights are informed by Perplexity's experience operating general-purpose agentic systems used by millions of users and thousands of enterprises in both controlled and open-world environments. Agent architectures change core assumptions around code-data separation, authority boundaries, and execution predictability, creating new confidentiality, integrity, and availability failure modes. We map principal attack surfaces across tools, connectors, hosting boundaries, and multi-agent coordination, with particular emphasis on indirect prompt injection, confused-deputy behavior, and cascading failures in long-running workflows. We then assess current defenses as a layered stack: input-level and model-level mitigations, sandboxed execution, and deterministic policy enforcement for high-consequence actions. Finally, we identify standards and research gaps, including adaptive security benchmarks, policy models for delegation and privilege control, and guidance for secure multi-agent system design aligned with NIST risk management principles.
title Security Considerations for Artificial Intelligence Agents
topic Machine Learning
Artificial Intelligence
Cryptography and Security
url https://arxiv.org/abs/2603.12230