A2ASecBench: A Protocol-Aware Security Benchmark for Agent-to-Agent Multi-Agent Systems
Tianhao Li, Chuangxin Chu, Yujia Zheng, Bohan Zhang, Neil Zhenqiang Gong, Chaowei Xiao
Abstract
Multi-agent systems (MAS) built on large language models (LLMs) increasingly rely on agent-to-agent (A2A) protocols to enable capability discovery, task orchestration, and artifact exchange across heterogeneous stacks. While these protocols promise interoperability, they also introduce new vulnerabilities. In this paper, we present the first comprehensive security evaluation of A2A-MAS. We develop a taxonomy and threat model that categorize risks into supply-chain manipulations and protocol-logic weaknesses, and we detail six concrete attacks spanning all A2A stages and components with impacts on confidentiality, integrity, and availability. Building on this taxonomy, we introduce A2ASECBENCH, the first A2Aspecific security benchmark framework capable of probing diverse and previously unexplored attack vectors. Our framework incorporates a dynamic adapter layer for deployment across heterogeneous agent stacks and downstream workloads, alongside a joint safety-utility evaluation methodology that explicitly measures the trade-off between harmlessness and helpfulness by pairing adversarial trials with benign tasks. We empirically validate our framework using official A2A Project demos across three representative high-stakes domains (travel, healthcare, and finance), demonstrating that the identified attacks are both pervasive and highly effective, consistently bypassing default safeguards. These findings highlight the urgent need for protocol-level defenses and standardized benchmarking to secure the next generation of agentic ecosystems. https://safo-lab.github.io/A2ASecBench/ Published as a conference paper at ICLR 2026 Mao et al., 2025; Du et al., 2025; Vaziry et al., 2025) , and multiple enterprise-grade products from different vendors have also emerged (detailed in Appendix D). These developments demonstrate that the A2A protocol is already making tangible real-world impact. However, the A2A ecosystem expands a protocol-level threat surface that lies beyond prompt-centric defenses. As shown in Figure 1 , threats can arise at the supply chain during discovery and selection (misleading capability claims or cloaked functions), and throughout task orchestration and artifact exchange (lifecycle manipulation, flooding, and malicious payloads embedded in artifacts). The risk is exacerbated by A2A's opaque execution model, where agents collaborate via declared capabilities and exchanged context without exposing internal logic, memory, or proprietary tools, rendering identity and capability claims difficult to independently verify (A2A Project, 2024). Once admitted, a spoofed or cloaked agent can induce a client to submit sensitive inputs, misroute or hijack tasks, withhold or corrupt partial results, launch denial-of-service (DoS) style task floods, or return artifacts that trigger downstream code execution or data exfiltration, thereby compromising confidentiality, integrity, and availability.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 499f2c50-8bdb-443c-be8f-7ba7a66fa095Builds on2
- G-Safeguard: A Topology-Guided Security Lens and Treatment on LLM-based Multi-agent SystemsShilong Wang, Guibin Zhang, Miao Yu, Guancheng Wan et al.ACL 2025 · 37 citations
- Agents Under Siege: Breaking Pragmatic Multi-Agent LLM Systems with Optimized Prompt AttacksRana Muhammad Shahroz, Zhen Tan, Sukwon Yun, Charles Fleming et al.ACL 2025 · 18 citations
Related papers
- MCP-SafetyBench: A Benchmark for Safety Evaluation of Large Language Models with Real-World MCP ServersXuanjun Zong, Zhiqi Shen, Lei Wang, Yunshi Lan et al.ICLR 2026 · 34 citations
- Agent Security Bench (ASB): Formalizing and Benchmarking Attacks and Defenses in LLM-based AgentsHanrong Zhang, Jingyuan Huang, Kai Mei, Yifei Yao et al.ICLR 2025
- MCP Security Bench (MSB): Benchmarking Attacks Against Model Context Protocol in LLM AgentsDongsen Zhang, Zekun Li, Xu Luo, Xuannan Liu et al.ICLR 2026 · 47 citations
- SEC-bench: Automated Benchmarking of LLM Agents on Real-World Software Security TasksHwiwon Lee, Ziqi Zhang, Hanxiao Lu, Lingming ZhangNeurIPS 2025 · 86 citations
- TAMAS: Benchmarking Adversarial Risks in Multi-Agent LLM SystemsIshan Kavathekar, Hemang Jain, Ameya Rathod, Ponnurangam Kumaraguru et al.ACL 2026 · 16 citations
