SoK: The Attack Surface of Agentic AI - Tools and Autonomy
A systematisation-of-knowledge paper maps the expanded attack surface of agentic AI — tool abuse, RAG poisoning, multi-agent manipulation — giving CISOs a structured threat taxonomy for risk governance.
Summary written by editorial AI · Source link below
arXiv:2603.22928v2 Announce Type: replace Abstract: Recent AI systems combine large language models with tools, external knowledge via retrieval-augmented generation (RAG), and even autonomous multi-agent decision loops. This agentic AI paradigm greatly expands capabilities - but also vastly enlarges the attack surface. In this systematization, we map out the trust boundaries and security risks of agentic LLM-based systems. We develop a comprehensive taxonomy of attacks spanning prompt-level in
Editorial Analysis
As agentic AI adoption accelerates, enterprises lack a unified threat model; this taxonomy provides the foundation for structured risk governance across tools, RAG, and autonomous loops.
Adopt the SoK taxonomy as a baseline for threat modelling all current and planned agentic AI deployments.
A comprehensive academic mapping of AI agent attack surfaces provides the threat taxonomy boards need to govern agentic AI risk.
Forward-looking interpretation drafted by editorial AI under human review — not a reproduction of the source. See methodology.
External link — opens at arXiv Crypto & Security in a new tab.
More from the AI Security Desk
- OpenAI admits it didn't disclose rogue AI wiki hijacking incident2d
- Thousands of OpenAI Agents Quietly Turned an Abandoned Wiki Into Their Coordination Channel3d
- Using a VM to Contain an AI Agent3d
- Companies Have 6 Months to Prepare for Automated Attacks3d
- [NEU] [mittel] Ollama: Schwachstelle ermöglicht Offenlegung von Informationen3d