Agent Security is a Systems Problem
Fuente:
arXiv
Salvato in:
| Autori principali: | , , , , , , , , , , , , , |
|---|---|
| Natura: | Preprint |
| Pubblicazione: |
2026
|
| Soggetti: | |
| Accesso online: | |
| Tags: |
Aggiungi Tag
Nessun Tag, puoi essere il primo ad aggiungerne!!
|
| _version_ | 1866914583068803072 |
|---|---|
| author | Christodorescu, Mihai Fernandes, Earlence Hooda, Ashish Jha, Somesh Rehberger, Johann Chaudhuri, Kamalika Fu, Xiaohan Shams, Khawaja Amir, Guy Choi, Jihye Choudhary, Sarthak Palumbo, Nils Labunets, Andrey Pandya, Nishit V. |
| author_facet | Christodorescu, Mihai Fernandes, Earlence Hooda, Ashish Jha, Somesh Rehberger, Johann Chaudhuri, Kamalika Fu, Xiaohan Shams, Khawaja Amir, Guy Choi, Jihye Choudhary, Sarthak Palumbo, Nils Labunets, Andrey Pandya, Nishit V. |
| contents | We take the position that agent security must be approached as a systems problem: the AI model powering the agent must be treated as an untrusted component, and security invariants must be enforced at the system level. Through this lens, efforts to increase model robustness (the dominant viewpoint in the community) are insufficient on their own. Instead, we must complement existing efforts with techniques from the systems security domain. Based on our experience as cybersecurity researchers in operating systems, networks, formal methods, and adversarial machine learning, we articulate a set of core principles, grounded in decades of systems security research, that provide a foundation for designing agentic systems with predictable guarantees. As evidence, we analyze eleven representative real-world attacks on agents and discuss how systems principles, if realized, could have prevented these attacks. We also identify the research challenges that stand in the way of implementing these principles in agents. |
| format | Preprint |
| id |
arxiv_https___arxiv_org_abs_2605_18991 |
| institution | arXiv |
| publishDate | 2026 |
| record_format | arxiv |
| spellingShingle | Agent Security is a Systems Problem Christodorescu, Mihai Fernandes, Earlence Hooda, Ashish Jha, Somesh Rehberger, Johann Chaudhuri, Kamalika Fu, Xiaohan Shams, Khawaja Amir, Guy Choi, Jihye Choudhary, Sarthak Palumbo, Nils Labunets, Andrey Pandya, Nishit V. Cryptography and Security Artificial Intelligence We take the position that agent security must be approached as a systems problem: the AI model powering the agent must be treated as an untrusted component, and security invariants must be enforced at the system level. Through this lens, efforts to increase model robustness (the dominant viewpoint in the community) are insufficient on their own. Instead, we must complement existing efforts with techniques from the systems security domain. Based on our experience as cybersecurity researchers in operating systems, networks, formal methods, and adversarial machine learning, we articulate a set of core principles, grounded in decades of systems security research, that provide a foundation for designing agentic systems with predictable guarantees. As evidence, we analyze eleven representative real-world attacks on agents and discuss how systems principles, if realized, could have prevented these attacks. We also identify the research challenges that stand in the way of implementing these principles in agents. |
| title | Agent Security is a Systems Problem |
| topic | Cryptography and Security Artificial Intelligence |
| url | https://arxiv.org/abs/2605.18991 |