arXiv AI

When Agents Act on Web3: An Attack-Surface Survey of MCP, Skills, and Tool Calling

The paper surveys the growing use of AI agents that modify external state via the Model Context Protocol (MCP) ecosystem, noting an increase from 27% to 65% of tool use. It argues that when such agents operate on public blockchains, the blockchain execution layer’s properties—irreversibility, signing authority, continuous autonomy, and sequence-level composition—reshape the threat model, making failures irreversible. The authors organize existing MCP-security literature into an attack-surface taxonomy, present a Web3 risk-mapping matrix linking attack classes to amplified impacts and mitigations, and conclude that current defenses are inadequate, stopping fewer than 30% of attacks and less than 3% of model-level safety failures. whyItMatters":"The study highlights that AI agents acting on Web3 introduce irreversible risks that conventional software security cannot address, underscoring the need for stronger, blockchain-aware safeguards."

arXiv AI
Sep 25

Blockchain-Enabled Artificial Intelligence and AI Agents for Secure Data Sharing and Cybersecurity Applications

The paper reviews four studies that combine blockchain and AI to secure data sharing, model integrity, and autonomous decision-making in distributed systems. It highlights how blockchain’s immutability, decentralized consensus, and verifiable provenance can address trust gaps in training data, real‑time monitoring, and automated code remediation. The authors propose a layered architecture integrating hardened models, blockchain‑anchored provenance, AI anomaly detection, and smart‑contract‑governed multi‑agent remediation, and outline open challenges in scalability, privacy‑transparency trade‑offs, and governance.

By Harsh Verma
arXiv AI
6d ago

Resource-Optimized and Energy-Aware Agentic AI Framework Anchored on Blockchain for Secure Software Supply Chains

The paper introduces a blockchain-backed agentic security framework that protects the entire software development lifecycle and the AI components monitoring it. It coordinates specialized security agents—covering source integrity, dependency and SBOM analysis, CI configuration auditing, artifact verification, and runtime policy evaluation—each powered by a large language model that interprets artifacts, reasons over tool outputs, and generates structured security reports. Every agent produces a cryptographically signed attestation recorded on a permissioned blockchain via smart contracts, creating an immutable attestation log, an agent registry, and an enforceable release‑policy module, while communication is secured through a consortium‑operated certificate authority.

By Toqeer Ali Syed, Asadullah Abdullah Khan
arXiv AI
Aug 26

Beyond the Mandate: A Systematic Security Analysis of the Agent Payments Protocol (AP2)

The paper presents a systematic security analysis of Google’s Agent Payments Protocol (AP2) version 2.0, focusing on its roles, transaction lifecycle, and deployment architectures. It identifies 48 threats across five attack families, scores them with the AIVSS, and demonstrates eight high‑risk threats with proof‑of‑concept attacks and mitigations. The study also introduces a deployment‑aware scanner to map threats to various checks, showing that signed mandates alone cannot guarantee user intent when pre‑authorization context is manipulated.

By Avital Aviv, Parth A. Gandh, Ron Bitton, Asaf Shabtai
arXiv AI
Jun 12

Who Pays the Price? Stakeholder-Centric Prompt Injection Benchmarking for Real-world Web Agents

arXiv:2606. 13385v1 Announce Type: cross Abstract: Web agents driven by large language models (LLMs) are increasingly deployed in real-world environments, where they operate over untrusted web content and execute actions with direct consequences.

By Zihao Wang, Yiming Li, Yutong Wu, Zheyu Liu, Kangjie Chen, Fok Kar Wai, Pin-Yu Chen, Vrizlynn L. L. Thing, Bo Li, Dacheng Tao, Tianwei Zhang
arXiv AI
Sep 2

Delegation Without Trust: An Empirical Gap Analysis of Identity, Authorization, and Runtime Governance in Multi-Agent LLM Systems

The paper examines the security challenges of delegating authority to autonomous LLM agents that act on users’ behalf. It introduces a threat model with four adversaries and eight security requirements, demonstrates that current frameworks (LangGraph, CrewAI, AutoGen, MCP) fail to meet these standards, and presents an authorization broker that blocks all identified threats with minimal overhead. The broker is shown to resist numerous attacks and limits compromised sub‑agents to their delegated tasks, and its principles are implemented in VotalAI’s LLM Shield.

By Panduranga Sai Varma Dantuluri, Jyotirmoy Sundi