Protocol-Level Attacks on Agentic Commerce Platforms: A Cross-Platform Taxonomy, AIP-Bench, and Unified Defense
Yedidel Louck
cs.CR
Submitted: 2026-07-23
Code: https://github.com/yedidel/aip-bench-public
License: http://arxiv.org/licenses/nonexclusive-distrib/1.0/
Terminology
Sources
- Formal Analysis and Supply Chain Security for Agentic AI Skills
- RAILS: Verification-Native Clearing For Agentic Commerce
- Infrastructure for the Agentic Web: Gap Analysis and Architecture from the Agentverse Platform
- Coral Protocol: Open Infrastructure Connecting The Internet of Agents
- Give Them an Inch and They Will Take a Mile:Understanding and Measuring Caller Identity Confusion in MCP-Based AI Systems
- The Attack and Defense Landscape of Agentic AI: A Comprehensive Survey
- Trust Without Trusting: A Recomputable Trust Protocol for Autonomous Agents
- Who Governs the Machine? A Machine Identity Governance Taxonomy (MIGT) for AI Systems Operating Across Enterprise and Geopolitical Boundaries
- Zero-Trust Runtime Verification for Agentic Payment Protocols: Mitigating Replay and Context-Binding Failures in AP2
- A402: Binding Cryptocurrency Payments to Service Execution for Agentic Commerce
- Mind the Gap: Time-of-Check to Time-of-Use Vulnerabilities in LLM-Enabled Agents
- Free-Riding the Agentic Web: A Systematic Security Analysis of x402 Payments
- Your Agent Is Mine: Measuring Malicious Intermediary Attacks on the LLM Supply Chain
- Agent Skills in the Wild: An Empirical Study of Security Vulnerabilities at Scale
- Securing LLM-Agent Long-Term Memory Against Poisoning: Non-Malleable, Origin-Bound Authority with Machine-Checked Guarantees
- Security Analysis of Agentic AI Communication Protocols: A Comparative Evaluation
- SoK: Security of Autonomous LLM Agents in Agentic Commerce
- Cryptographic Registry Provenance: Structural Defense Against Dependency Confusion in AI Package Ecosystems
- MCP-38: A Comprehensive Threat Taxonomy for Model Context Protocol Systems (v1.0)
- Before the Tool Call: Deterministic Pre-Action Authorization for Autonomous AI Agents
Related papers
- SoK: AI-Augmented Binary Reversing
- Relaxed Sender Anonymity for CBDC Interbank Settlement: A Zero-Knowledge Approach on Permissioned EVM
- Calibration-Family Overfit: Why Trusted Sabotage Monitors Don't Transfer Across Lineages
- Efficient Fuzzy PSI under One-Sided Assumptions
- Sealing the Audit-Runtime Gap for LLM Skills
- Token Composition: A Graph Based on EVM Logs