Attack and Defense Landscape of Agentic AI (2026) logo

Attack and Defense Landscape of Agentic AI (2026)

Free

Dawn Song (UC Berkeley) et al. — first complete security survey for agentic AI systems (LLM + external tools/components); establishes threat model covering full attack surface and defense mechanisms; USENIX Security 2026

FreeFree tier
Type
Open Source

About Attack and Defense Landscape of Agentic AI (2026)

This paper presents the first systematic and comprehensive survey of AI agent security, focusing on LLM-based agents combined with non-AI system components. It analyzes the design space, attack landscape, and defense mechanisms for secure AI agent systems, establishes a systematic framework for understanding security risks and defense strategies, and conducts case studies to identify existing gaps and open challenges. Accepted to USENIX Security 2026, the survey serves as a foundation for building secure agentic systems and advancing research in this critical area.

Key Features

Systematic framework for understanding AI agent security risks and defense strategies
Comprehensive analysis of the attack landscape for LLM-based agentic systems
Survey of defense mechanisms for secure AI agent systems
Case studies identifying existing gaps in securing agentic AI
Discussion of open challenges in the emerging domain

Pros & Cons

Pros
  • First systematic and comprehensive survey in the field
  • Establishes a foundational threat model and defense taxonomy
  • Provides actionable insights for building secure agentic systems
  • Accepted at top security venue (USENIX Security 2026)
Cons
  • Survey focuses primarily on LLM-based agents, may not cover all agent types
  • Limited to academic analysis; no practical implementation or tooling provided
  • Rapidly evolving field may outdate some findings

Best For

Academic research on AI agent securitySecurity auditing and threat modeling for agentic systemsDesign of secure LLM-based agent architecturesUnderstanding vulnerabilities in tool-integrated AI systems

FAQ

What is this paper about?
It is a comprehensive survey of security challenges in AI agent systems, covering attack surfaces, defense mechanisms, and a systematic framework for secure agent design.
Where is this paper published?
The paper is accepted to USENIX Security 2026 and is available as an extended version on arXiv.
What types of AI agents does it cover?
The survey focuses on agents that combine large language models (LLMs) with non-AI system components, such as external tools and APIs.