PulseExploreJournal ClubDebatesTrendingResearchersJournals
Instagram
HomeExploreJournal ClubTrending
Synapse
⌘+K
Synapse
May 27, 20260 citationsOpen Access

Protocol Pivoting: Cross-Protocol Attack Escalation in Agentic AI Systems

View Full Paper
SMSyed Anas Mohiuddin

Key Points

  • This research aims to explore a new attack class called Protocol Pivoting, revealing vulnerabilities in agentic AI communication protocols.
  • Identification and formalization of Protocol Pivoting as a multi-step attack.
  • Analysis of three specific exploitation scenarios across communication protocols.
  • Development of a unified security framework with mitigations against Protocol Pivoting.
  • Demonstrated that trust assumptions between protocols lead to privilege escalation, enabling higher-level access.
  • Showcased vulnerabilities through malicious agent impersonation that facilitate capability injection.
  • Proposed three protocol-agnostic security mitigations to effectively address the identified vulnerabilities.

Abstract

Modern agentic AI deployments run several agent communication protocols in parallel: the Model Context Protocol (MCP) for tool access, Google's Agent-to-Agent (A2A) protocol for inter-agent delegation, and emerging standards such as the Agent Network Protocol (ANP). Each was designed independently, with a security model that assumes it operates alone. We identify and formalize a new attack class we term Protocol Pivoting—a multi-step attack in which an adversary gains initial access through one protocol, exploits trust assumptions between protocols, and escalates to capabilities only accessible via a different protocol. We present three concrete Protocol Pivoting scenarios: MCP to A2A privilege escalation via implicit trust delegation, A2A to MCP capability injection via malicious agent impersonation, and cross-protocol prompt injection chains where context from one protocol influences behavior in another. We analyze why existing defenses fail against Protocol Pivoting, and propose a unified cross-protocol security framework including a formal trust boundary model and three protocol-agnostic mitigations.

Ask AI
Helpful
Bookmark
Share
View Full Paper

Cite This Study

Syed Anas Mohiuddin (2026) studied this question.

synapsesocial.com/papers/6a168b040c924ddd1bd59c3ahttps://doi.org/10.5281/zenodo.20371151
Ask AI
Helpful
Bookmark
Share
View Full Paper