2602.19555v1 Feb 23, 2026 cs.CR

자율 AI를 사이버 보안 공격 대상으로: 런타임 공급망에서의 위협, 악용, 및 방어

Agentic AI as a Cybersecurity Attack Surface: Threats, Exploits, and Defenses in Runtime Supply Chains

Shiqi Yang
Shiqi Yang
Citations: 29
h-index: 3
Wenting Yang
Wenting Yang
Citations: 23
h-index: 3
Yichen Liu
Yichen Liu
Citations: 8
h-index: 1
Chen Ji
Chen Ji
Citations: 34
h-index: 3
Xia Jiang
Xia Jiang
Citations: 184
h-index: 3

대규모 언어 모델(LLM)을 기반으로 구축된 자율 시스템은 텍스트 생성 기능을 넘어 정보를 자율적으로 검색하고 도구를 실행합니다. 이러한 런타임 실행 모델은 공격 표면을 빌드 타임의 산물에서 추론 타임의 의존성으로 이동시키며, 이는 에이전트가 신뢰할 수 없는 데이터 및 확률적 기능 해결을 통해 조작될 위험에 노출됩니다. 기존 연구가 모델 수준의 취약점에 초점을 맞춘 반면, 순환적이고 상호 의존적인 런타임 동작에서 발생하는 보안 위험은 여전히 분산되어 있습니다. 본 연구에서는 이러한 위험을 통합된 런타임 프레임워크 내에서 체계화하고, 위협을 데이터 공급망 공격(일시적인 컨텍스트 주입 및 지속적인 메모리 오염)과 도구 공급망 공격(발견, 구현, 및 실행)으로 분류합니다. 또한, 에이전트가 코드 수준의 결함을 악용하지 않고도 자체적으로 전파되는 생성형 웜의 매개체가 되는 '바이러스 에이전트 루프'를 식별합니다. 마지막으로, 컨텍스트를 신뢰할 수 없는 제어 흐름으로 간주하고, 의미 추론이 아닌 암호학적 출처를 통해 도구 실행을 제한하는 제로 트러스트 런타임 아키텍처를 제안합니다.

Original Abstract

Agentic systems built on large language models (LLMs) extend beyond text generation to autonomously retrieve information and invoke tools. This runtime execution model shifts the attack surface from build-time artifacts to inference-time dependencies, exposing agents to manipulation through untrusted data and probabilistic capability resolution. While prior work has focused on model-level vulnerabilities, security risks emerging from cyclic and interdependent runtime behavior remain fragmented. We systematize these risks within a unified runtime framework, categorizing threats into data supply chain attacks (transient context injection and persistent memory poisoning) and tool supply chain attacks (discovery, implementation, and invocation). We further identify the Viral Agent Loop, in which agents act as vectors for self-propagating generative worms without exploiting code-level flaws. Finally, we advocate a Zero-Trust Runtime Architecture that treats context as untrusted control flow and constrains tool execution through cryptographic provenance rather than semantic inference.

8 Citations
0 Influential
1.5 Altmetric
15.5 Score
Original PDF

No Analysis Report Yet

This paper hasn't been analyzed by Gemini yet.

Log in to request an AI analysis.

댓글

댓글을 작성하려면 로그인하세요.

아직 댓글이 없습니다. 첫 번째 댓글을 남겨보세요!