---
格式版本: 2
标题: "Rethinking Agent Security as a Networking Problem"
原文链接: "https://arxiv.org/abs/2608.12172"
发布日期: "2026-08-12"
发布时间校准状态: "found"
发布时间需复核: "否"
发布时间来源: "rule:local:strict_original_body"
发布时间证据: "**\\[v1\\]** Wed, 12 Aug 2026 15:29:51 UTC (747 KB)"
发布时间校准原因: "规则确认唯一严格发布时间，来源 local:strict_original_body"
发布时间校准置信度: "high"
发布时间候选数量: 18
发布时间严格候选数量: 6
发布时间原页读取状态: "source template page reused from URL open"
发布时间未找到原因: ""
发布时间校准时间: "2026-08-13T18:32:54+08:00"
发布时间仲裁状态: "skipped"
发布时间仲裁尝试次数: 0
发布时间仲裁耗时毫秒: 0
发现时间: "2026-08-13T18:24:32+08:00"
入库时间: "2026-08-13T10:32:54.892Z"
来源平台: "arXiv 学术论文搜索"
搜索渠道: "source_template"
搜索词: "https://arxiv.org/search/?query=AI&searchtype=all"
匹配关键词:
  - "AI"
相关厂家:
  []
相关专家:
  []
内容类型: "网页"
抓取工具: "Free Fetch + Defuddle"
清洗工具: "Defuddle Markdown + Defuddle/Readability 正文提取"
原始附件:
  []
AI质检状态: "评分失败"
AI评分尝试次数: 1
AI评分错误类型: "service_error"
AI评分错误: "LLM call failed; tried model chain: ali-deepseek-v4-flash -> tx-deepseek-v4-flash | Model ali-deepseek-v4-flash failed 500: {\"error\":{\"code\":\"\",\"message\":\"Database error, please contact the administrator (request id: 202608131032583721833768268d9d6C1W9ENfA)\",\"type\":\"new_api_error\"}} | Model tx-deepseek-v4-flash failed 500: {\"error\":{\"code\":\"\",\"message\":\"Database error, please contact the administrator (request id: 202608131032589459836408268d9d62uR9ry75)\",\"type\":\"new_api_error\"}}"
AI评分开始时间: "2026-08-13T10:32:55.525Z"
AI评分结束时间: "2026-08-13T10:32:59.219Z"
AI摘要: "该论文提出将AI代理安全重新构想为网络问题，批评现有依赖代理自身的防御机制因LLM行为不确定而易受提示注入攻击。作者借鉴网络领域的集中控制、能力访问和零信任原则，主张结合确定性执行与语义上下文策略，并给出参考架构。"
AI摘要模型: "ali-deepseek-v4-flash"
AI摘要时间: "2026-09-07T03:40:09.971Z"
采集批次: "2026年8月13日18点24分27秒"
采集批次ID: "20260813-182427-1564e572"
去重键: "https://arxiv.org/abs/2608.12172"
---

## Computer Science > Multiagent Systems

## Title:Rethinking Agent Security as a Networking Problem

Authors:[Van Tran](https://arxiv.org/search/cs?searchtype=author&query=Tran,+V), [Taveesh Sharma](https://arxiv.org/search/cs?searchtype=author&query=Sharma,+T), [Tajveer Singh Dhesi](https://arxiv.org/search/cs?searchtype=author&query=Dhesi,+T+S), [Nick Feamster](https://arxiv.org/search/cs?searchtype=author&query=Feamster,+N)

[View PDF](https://arxiv.org/pdf/2608.12172) [HTML (experimental)](https://arxiv.org/html/2608.12172v1)

> Abstract:AI agents are rapidly becoming more capable and widely deployed, promising substantial gains in productivity and enabling new classes of applications. However, their growing autonomy also introduces significant privacy and security risks. Existing defenses are predominantly agent-centric, relying on the agent itself to detect threats and enforce privacy and security policies. This approach is fundamentally limited because it entrusts policy enforcement to AI agents whose LLM-driven behavior is inherently nondeterministic and vulnerable to manipulation through attacks such as prompt injection. As a result, current defenses cannot reliably prevent privacy and security threats, highlighting a critical need for a new solution to securing AI agent systems.  
> The networking community has long grappled with similar challenges and offers insightful principles we can borrow to design a more secure AI agent system. These include centralized control with distributed enforcement, capability-based access for mediating requests to sensitive resources, and least privilege through zero-trust enforcement. Historically, these principles have provided strong deterministic guarantees for networked systems. However, these principles alone are insufficient for AI agents because the safety and appropriateness of an agent's actions often depend on semantic context beyond the expressiveness of static rules.  
> Building on these principles, we advocate for a systematic approach to AI agent security that combines deterministic enforcement mechanisms, which provide strong security guarantees, with semantic, context-aware policies that enable nuanced decision-making. We then present a reference architecture and identify key research questions and future directions to guide the design of secure and privacy-preserving AI agent systems.

| Subjects: | Multiagent Systems (cs.MA) |
| --- | --- |
| Cite as: | [arXiv:2608.12172](https://arxiv.org/abs/2608.12172) \[cs.MA\] |
|  | (or [arXiv:2608.12172v1](https://arxiv.org/abs/2608.12172v1) \[cs.MA\] for this version) |
|  | [https://doi.org/10.48550/arXiv.2608.12172](https://doi.org/10.48550/arXiv.2608.12172) |

## Submission history

From: Van Tran \[[view email](https://arxiv.org/show-email/8907cd08/2608.12172)\]  
**\[v1\]** Wed, 12 Aug 2026 15:29:51 UTC (747 KB)

[Which authors of this paper are endorsers?](https://arxiv.org/auth/show-endorsers/2608.12172) | Disable MathJax ([What is MathJax?](https://info.arxiv.org/help/mathjax.html))
