Agent Security is a Systems Problem

Fuente: arXiv
Salvato in:
Dettagli Bibliografici
Autori principali: Christodorescu, Mihai, Fernandes, Earlence, Hooda, Ashish, Jha, Somesh, Rehberger, Johann, Chaudhuri, Kamalika, Fu, Xiaohan, Shams, Khawaja, Amir, Guy, Choi, Jihye, Choudhary, Sarthak, Palumbo, Nils, Labunets, Andrey, Pandya, Nishit V.
Natura: Preprint
Pubblicazione: 2026
Soggetti:
Accesso online:
Tags: Aggiungi Tag
Nessun Tag, puoi essere il primo ad aggiungerne!!
_version_ 1866914583068803072
author Christodorescu, Mihai
Fernandes, Earlence
Hooda, Ashish
Jha, Somesh
Rehberger, Johann
Chaudhuri, Kamalika
Fu, Xiaohan
Shams, Khawaja
Amir, Guy
Choi, Jihye
Choudhary, Sarthak
Palumbo, Nils
Labunets, Andrey
Pandya, Nishit V.
author_facet Christodorescu, Mihai
Fernandes, Earlence
Hooda, Ashish
Jha, Somesh
Rehberger, Johann
Chaudhuri, Kamalika
Fu, Xiaohan
Shams, Khawaja
Amir, Guy
Choi, Jihye
Choudhary, Sarthak
Palumbo, Nils
Labunets, Andrey
Pandya, Nishit V.
contents We take the position that agent security must be approached as a systems problem: the AI model powering the agent must be treated as an untrusted component, and security invariants must be enforced at the system level. Through this lens, efforts to increase model robustness (the dominant viewpoint in the community) are insufficient on their own. Instead, we must complement existing efforts with techniques from the systems security domain. Based on our experience as cybersecurity researchers in operating systems, networks, formal methods, and adversarial machine learning, we articulate a set of core principles, grounded in decades of systems security research, that provide a foundation for designing agentic systems with predictable guarantees. As evidence, we analyze eleven representative real-world attacks on agents and discuss how systems principles, if realized, could have prevented these attacks. We also identify the research challenges that stand in the way of implementing these principles in agents.
format Preprint
id arxiv_https___arxiv_org_abs_2605_18991
institution arXiv
publishDate 2026
record_format arxiv
spellingShingle Agent Security is a Systems Problem
Christodorescu, Mihai
Fernandes, Earlence
Hooda, Ashish
Jha, Somesh
Rehberger, Johann
Chaudhuri, Kamalika
Fu, Xiaohan
Shams, Khawaja
Amir, Guy
Choi, Jihye
Choudhary, Sarthak
Palumbo, Nils
Labunets, Andrey
Pandya, Nishit V.
Cryptography and Security
Artificial Intelligence
We take the position that agent security must be approached as a systems problem: the AI model powering the agent must be treated as an untrusted component, and security invariants must be enforced at the system level. Through this lens, efforts to increase model robustness (the dominant viewpoint in the community) are insufficient on their own. Instead, we must complement existing efforts with techniques from the systems security domain. Based on our experience as cybersecurity researchers in operating systems, networks, formal methods, and adversarial machine learning, we articulate a set of core principles, grounded in decades of systems security research, that provide a foundation for designing agentic systems with predictable guarantees. As evidence, we analyze eleven representative real-world attacks on agents and discuss how systems principles, if realized, could have prevented these attacks. We also identify the research challenges that stand in the way of implementing these principles in agents.
title Agent Security is a Systems Problem
topic Cryptography and Security
Artificial Intelligence
url https://arxiv.org/abs/2605.18991