Attack and Defense Landscape of Agentic AI (2026)
FreeDawn Song (UC Berkeley) et al. — first complete security survey for agentic AI systems (LLM + external tools/components); establishes threat model covering full attack surface and defense mechanisms; USENIX Security 2026
About Attack and Defense Landscape of Agentic AI (2026)
This paper presents the first systematic and comprehensive survey of AI agent security, focusing on LLM-based agents combined with non-AI system components. It analyzes the design space, attack landscape, and defense mechanisms for secure AI agent systems, establishes a systematic framework for understanding security risks and defense strategies, and conducts case studies to identify existing gaps and open challenges. Accepted to USENIX Security 2026, the survey serves as a foundation for building secure agentic systems and advancing research in this critical area.
Key Features
Pros & Cons
- First systematic and comprehensive survey in the field
- Establishes a foundational threat model and defense taxonomy
- Provides actionable insights for building secure agentic systems
- Accepted at top security venue (USENIX Security 2026)
- Survey focuses primarily on LLM-based agents, may not cover all agent types
- Limited to academic analysis; no practical implementation or tooling provided
- Rapidly evolving field may outdate some findings