PulseExploreJournal ClubDebatesTrendingResearchersJournals
Instagram
HomeExploreJournal ClubTrending
Synapse
⌘+K
Synapse
April 3, 20266 citationsOpen Access

Beyond Identity Governance: A Protocol-Level Security Testing Framework for Multi-Agent AI Systems

View Full Paper
MSMichael Saleme

Key Points

  • The aim is to test the decision-making of multi-agent AI systems under adversarial conditions at the protocol level.
  • Conducted controlled experiments using Envoy Gateway and backend architecture.
  • Evaluated 209 executable security tests across four protocols (MCP, A2A, L402, x402).
  • Applied NIST AI 800-2 evaluation methodology to assess security measures.
  • Conventional defense-in-depth shows no mitigation against agent protocol-layer attacks.
  • Gateway-layer defenses create false confidence by masking application-layer vulnerabilities.
  • AI-generated testing tools can yield dangerous false results that identity governance cannot detect.

Abstract

Enterprise AI agent systems are scaling rapidly, communicating via new wire protocols (MCP, A2A) and executing financial transactions autonomously (L402, x402). Existing security tools address model-level vulnerabilities (prompt injection, jailbreaks) or enforce identity and access policies (authorization, sandboxing, scope control). Neither approach tests whether agent systems make correct decisions under adversarial conditions at the protocol layer. We present empirical evidence from controlled experiments against an Envoy Gateway + backend architecture demonstrating three findings: (1) conventional defense-in-depth provides no measurable mitigation in tested configurations for agent protocol-layer attacks, with identical MCP vulnerability profiles observed through proxied and direct testing; (2) gateway-layer defenses can mask application-layer vulnerabilities, creating false confidence in security posture that collapses when gateway configurations change; and (3) AI-generated security testing tools can produce structurally valid but functionally dangerous false-pass results undetectable by identity governance alone. We formalize these findings through the WHO vs. HOW governance gap: existing security layers that address WHO may access agent systems provide no measurable mitigation for HOW those agents make decisions under adversarial conditions. We present an open-source evaluation framework with 209 executable security tests across four agent communication and payment protocols (MCP, A2A, L402, x402), aligned with NIST AI 800-2 evaluation methodology, as the instrument for these findings. Three-run progression data (72% to 100% pass rate) demonstrates that protocol-level findings translate to measurable security improvements when the testing methodology addresses the correct architectural layer.

Ask AI
Helpful
Bookmark
Share
View Full Paper

Cite This Study

Michael Saleme (2026) studied this question.

synapsesocial.com/papers/69cf5f505a333a821460e70dhttps://doi.org/10.5281/zenodo.19343034
Ask AI
Helpful
Bookmark
Share
View Full Paper

Also Consider

Synapse has enriched 5 closely related papers on similar clinical questions. Consider them for comparative context:

  1. 1The Governance Gap: A Systematic Analysis of Architectural Deficiencies in AI Agent Security Frameworks2026
  2. 2Governing Autonomous AI Agents: A Two-Layer Architecture2026
  3. 3Toward a Unified Interoperability Framework for Autonomous AI Agent Ecosystems: MCP, A2A, ACP, and ANP2026
  4. 4A Path-Dependent, Multi-Layered Architecture for Runtime Governance and Post-Quantum Cryptographic Assurance of Autonomous AI Agents2026
  5. 5How Secure Are Production AI Agents? A Systematic Audit, Threat Taxonomy, and Defense Framework2026