{"id":"8a731cfe-3b9d-40e6-9952-521bdd6cb1a2","arxiv_id":"2505.08807","paper_version":1,"verdict":"CONDITIONAL","confidence":"MODERATE","novelty_score":3.0,"correctness_risk":"low","formal_verification":"none","parameter_count":0,"one_line_summary":"A survey cataloging identity, trust, embodied, and privacy threats in Internet of Agents systems, along with countermeasures and research gaps.","lead":"This paper surveys the security and privacy threats in the Internet of Agents, an emerging network of AI agents that collaborate autonomously. It organizes attacks and defenses into four categories and lists open challenges for building trustworthy agent ecosystems.","discovery_kind":"review","skeptic_critique":{"model":"deepseek-v4-flash","headline":"The IoA-specificity claim is under-supported: Free-Riding (Table III) cites a federated-learning paper unrelated to agent cooperation, and Knowledge Poisoning cites a general RAG attack without an agent-to-agent scenario.","rationale":"The strongest claim is a map of the IoA security landscape. For that map to be worth more than a relabeling, each mapped threat should be traceable to a source that demonstrates it in an IoA or at least multi-agent setting, or the paper should explicitly argue why transfer is valid. The most concrete failure is the free-riding entry: the cited reference is about federated learning, and the surrounding text offers no IoA citation at all. This is not a stylistic issue; it means an entire threat category in the taxonomy rests on no evidentiary support. The reader's weakest assumption identified the same general transfer problem, and PoisonedRAG is a good example; I would extend it to the free-riding cell. On the positive side, the paper does contain real IoA-adjacent material: MCP tool-poisoning [27], the A2A Sybil scenario in Section III, and protocol descriptions in Section II. Those give the survey partial grounding. But the central claim of comprehensiveness is undermined by the absence of a stated literature-selection method and by at least one demonstrably unrelated reference. I would keep the reader's CONDITIONAL verdict: the survey is usable as an organizational scaffold, but should not be treated as a validated IoA threat taxonomy until the reference mapping is corrected and IoA-specificity is demonstrated.","tokens_in":16243,"tokens_out":5532,"duration_ms":55207,"concrete_test":"Retrieve reference [59] and read its title, abstract, and experimental setup; record whether it describes free-riding by agents in an IoA or multi-agent LLM cooperation scenario. Independently, classify each row of Table III by the original paper's experimental setting (agent-to-agent vs. single-agent/generic). If [59] contains no IoA free-riding attack, or if fewer than half of Table III's rows involve two or more interacting agents, then the paper's claim of an IoA-specific threat taxonomy is not established.","verdict_should_be":"UNCHANGED","load_bearing_attack":"To support the abstract's claim of 'distinct vulnerabilities' and a 'comprehensive examination,' the survey must show that the threats in its taxonomy actually arise in an IoA/agent-to-agent setting and are not simply relabeled single-agent LLM or cyber-physical attacks. That condition fails for at least two concrete cells. Section IV's 'Free-Riding Attack' bullet describes a selfish agent withholding effort in cooperative IoA tasks, and Table III maps this threat to 'Coalition game, Shapley value' with reference [59], Wang et al., 'Social-aware clustered federated learning with customized privacy preservation.' That paper addresses federated-learning incentive design, not an IoA or multi-agent LLM cooperation setting; it provides no support for a free-riding attack or a Shapley-value defense in IoA. Section IV's 'Knowledge Poisoning' bullet cites PoisonedRAG [30], whose original evaluation targets RAG pipelines generally; the survey does not describe any modified IoA threat model or multi-agent experiment. Similar transfers appear elsewhere (e.g., voice forgery [6] and sensor attacks [43]-[47] are general CPS/voice attacks). Because the survey states no selection methodology, the 'comprehensive' claim cannot be independently checked, and the taxonomy's organizing value depends on these transfer arguments holding. The concern is not that IoA is irrelevant, but that the paper has not yet demonstrated the IoA-specific instantiations its central claim requires.","agreement_with_reader":"partial"},"referee_report":{"model":"deepseek-v4-flash","summary":"This paper is a survey of security and privacy issues in the Internet of Agents (IoA). It proposes a four-part taxonomy of threats—identity authentication, cross-agent trust, embodied security, and privacy—illustrates each category with recent attack and defense examples, and concludes with open challenges and future research directions. The paper positions itself against prior LLM-agent security surveys in Table I and summarizes its taxonomy in Fig. 1, with supporting detail in Sections III–VI and a consolidated threat/defense table in Table III.","tokens_in":16506,"tokens_out":3842,"duration_ms":36570,"significance":"If its central claim is accepted, the survey would offer a useful map of a rapidly emerging field and a starting point for researchers working on IoA-specific defenses. The paper's strengths are its breadth of recent references, concrete attack examples (e.g., Foice, Breaking Agents, RAG-Thief, and MEMS sensor attacks), clear graphical summaries, and a helpful comparison with prior surveys. It contains no derivations or empirical evaluations, so its value is organizational and agenda-setting rather than technical. However, that value depends on the claim that the surveyed threats are genuinely IoA-specific; as it stands, several taxonomy entries are supported only by work on general RAG, federated learning, or cyber-physical systems, which leaves the central contribution under-substantiated.","major_comments":[{"comment":"The 'Free-Riding Attack' entry is not supported by its cited reference. Section IV describes a selfish agent withholding effort in cooperative IoA tasks, but Table III maps this threat to 'Coalition game, Shapley value' and cites [59], Wang et al., 'Social-aware clustered federated learning with customized privacy preservation,' which addresses incentive design in federated learning and does not describe free-riding attacks or Shapley-value defenses in an agent-to-agent LLM/IoA setting. To sustain this taxonomy cell, the paper needs either a directly relevant IoA reference or an explicit argument for why the federated-learning result transfers.","section":"Section IV, Table III"},{"comment":"The claim that PoisonedRAG [30] targets 'external knowledge bases in IoA' misstates the original work. Zou et al. present PoisonedRAG as a knowledge-poisoning attack on retrieval-augmented generation systems generally, and the survey provides no agent-to-agent poisoning scenario or modified threat model. Table III repeats this mapping. Since knowledge poisoning is one of the central cross-agent trust threats, the IoA-specific instantiation needs to be demonstrated rather than asserted.","section":"Section IV, 'Knowledge Poisoning' bullet"},{"comment":"The abstract's claim of 'distinct vulnerabilities compared to traditional networks' and the taxonomic boundaries in Fig. 1 are not backed by a stated methodology. There is no description of how references were selected, how threats were classified as IoA-specific, or how transfer from single-agent LLM or cyber-physical systems was justified. As a result, several entries read as relabelings: voice forgery [6] and the sensor attacks [43]–[47] are general voice/CPS attacks, and their amplification in IoA is asserted in prose rather than shown. A short methodology or inclusion-criteria paragraph would make the 'comprehensive' claim checkable and would distinguish genuine IoA-specific threats from inherited ones.","section":"Section II-C, Fig. 1"}],"minor_comments":[{"comment":"The phrase 'Zhang et al. et al. [17]' contains a duplicated 'et al.' and should read 'Zhang et al. [17]'.","section":"Section I"},{"comment":"The text says 'as shown in Fig. 2(b),' but Fig. 2(b) is labeled 'Sybil Attack'; the impersonation attack is not separately depicted, so the figure callout should be corrected or the figure extended.","section":"Section III, 'Impersonation Attacks'"},{"comment":"The phrase 'through through physical defense' contains a duplicated word and should read 'through physical defense.'","section":"Section V, 'Defenses'"},{"comment":"The sentence 'Existing defenses of IoA privacy threats involves two complementary strategies' has a subject-verb agreement error; 'involves' should be 'involve.'","section":"Section VI, 'Defenses'"},{"comment":"The lesson-learned bullet says 'access control mechanisms is essential' and 'provides tamper-resistant identity management'; both should agree in number with their subjects.","section":"Section VII"}],"recommendation":"major_revision","confidential_remarks":"The manuscript would benefit from tightening its novelty claim relative to prior LLM-agent security surveys, since the current version overstates the distinctness of the IoA threat surface. I also note a cluster of self-citations ([1], [59]) used as background; this is not problematic by itself, but the survey's own prior work should not be the sole support for a taxonomy cell, as happens in the free-riding entry. The revision should either supply direct IoA evidence or soften the claimed scope."},"author_rebuttal":null,"desk_editor":{"model":"deepseek-v4-flash","letter":"The paper is what it says on the tin—a survey of security and privacy in the Internet of Agents—and for someone entering the area it is genuinely useful. The protocol overview (MCP, A2A, ANP, Agora) and the four-way split (identity, cross-agent trust, embodied, privacy) make the space easy to navigate. The recent references are mostly real and relevant, and the open-challenges section is a reasonable place for a student to start. It deserves a serious referee.\n\nNow the soft spots. The survey's central claim—that IoA has 'distinct vulnerabilities compared to traditional networks'—is not supported by the examples given. The stress-test note is right on both concrete cells. Table III maps Free-Riding to [59], Wang et al.'s federated-learning paper, which has nothing to do with agents withholding effort in cooperative IoA tasks; the Section IV bullet is a description with no citation. Knowledge Poisoning cites PoisonedRAG, a general RAG attack; the paper asserts it targets IoA but gives no A2A scenario or modification. The same pattern repeats: Foice is voice-authentication spoofing, and the sensor attacks are standard CPS attacks. That is okay if the paper said 'threats inherited by agents' rather than 'distinct vulnerabilities,' but as written the abstract overclaims.\n\nAlso, there is no methodology. No search strategy, inclusion criteria, or period is stated. 'Comprehensive' is therefore a claim you cannot check. For a survey in a young field that may be tolerable, but the authors should either add a methods paragraph or soften the word.\n\nWhere I disagree with the stress-tester: this is not a load-bearing flaw in the sense of invalidating the survey's organizing value. The taxonomy is still a reasonable way to group threats an IoA practitioner should think about. The problem is presentation and citation discipline, not the whole project. If the authors relabel the contribution as a scoping review of threats applicable to agent systems, and fix the citations, the paper works.\n\nWho it is for: students and researchers new to agent security; also useful for research-direction brainstorming. I would not cite it as evidence for a claim that IoA creates new vulnerabilities. I would send it to peer review, with a request for major revision.","headline":"A useful map of a young field, but the 'distinct vulnerabilities' claim overreaches: the taxonomy repackages known single-agent and CPS threats, and at least two table entries cite papers that do not support the IoA framing.","tokens_in":16995,"tokens_out":3067,"would_cite":false,"duration_ms":28791,"reading_group":"yes","serious_thinker":"yes","would_accept_peer_review":true},"rs_alignment":null,"lean_confirmation":null,"pith_extraction":{"msc":[],"pacs":[],"model":"deepseek-v4-flash","headline":"This paper claims that the Internet of Agents has a security and privacy threat landscape distinct from both traditional networks and isolated LLM agents, and organizes it into four categories with defenses and open challenges.","keywords":["Internet of Agents","AI agent security","LLM agent threats","identity authentication","cross-agent trust","embodied security","privacy leakage","agent communication protocols"],"falsifier":"A concrete disconfirmation would be a systematic audit showing that every attack in the taxonomy succeeds with equal or greater ease against a single LLM agent or an ordinary IoT device with no agent-to-agent coordination involved; that would collapse the claimed IoA-specific threat landscape into a relabeling of existing categories.","tokens_in":16053,"feed_emoji":"🛡️","tokens_out":6011,"duration_ms":57061,"temperature":0.7,"pith_summary":"The paper sets out to establish that the Internet of Agents (IoA)—an emerging web in which AI agents discover, negotiate with, and coordinate across each other—has a security and privacy threat landscape of its own, distinct from both conventional networks and single-agent LLM systems. It organizes that landscape into four families: identity authentication threats, cross-agent trust issues, embodied security, and privacy risks. For each family it catalogs concrete attacks, including voice forgery from a face image, hallucination cascades across chained agents, sensor spoofing of drones, and extraction of private retrieval-augmented-generation data, and it reviews defensive measures. If the taxonomy is right, it gives system builders a common vocabulary for what can go wrong in agent networks and where defenses should sit.","feed_headline":"Four threat fronts define Internet of Agents security","feed_subtitle":"A survey groups attacks on identity, trust, physical agents, and privacy, then reviews defenses and open gaps.","key_machinery":"The organizing machinery is the four-part threat taxonomy itself, anchored in an account of what makes IoA different: large-model foundations, decentralization, task-driven cooperation, semantic-aware interaction, and cyber-physical coupling. The taxonomy is populated with named attack families, such as hallucination cascade, contextual backdoor, and RAG-Thief, and paired with corresponding defense families, including access control, decentralized identifiers with verifiable credentials, RAG grounding, multi-agent audit and debate, topology isolation, sensor redundancy, world-model simulation, multimodal consistency validation, privacy pre-assessment, and output intervention. These pairings are what let the survey claim both that the threat space is structured and that mitigations can be mapped onto it.","core_discovery":"The paper's central claim is that the IoA introduces material new attack surfaces because agents are autonomous, decentralized, task-driven, communicate through semantically rich natural-language protocols, and often control physical systems. The resulting taxonomy has four parts. Identity authentication threats include identity forgery, impersonation, Sybil attacks, privilege escalation, and intent deception. Cross-agent trust issues include hallucination cascades, knowledge poisoning, adversarial inputs, jailbreaks, prompt injection, free-riding, and collusion. Embodied security includes sensor attacks, contextual backdoors, and cross-domain safety misalignment, where an agent refuses a harmful request in words but still emits executable dangerous action code. Privacy threats include contextual inference, RAG-based data extraction, and memorization of personally identifiable information. The paper also argues that defenses must be dynamically adaptive rather than static, and should span identity, communication, inference, and actuation layers.","pith_inferences":["A natural next step beyond the survey would be to benchmark each listed attack in paired single-agent versus multi-agent settings, isolating which threats are genuinely IoA-specific rather than inherited from LLM agents or general networked systems.","The 'threat cascade' and 'full-process poisoning' challenges could be formalized as propagation problems on agent graphs, making it possible to measure how misinformation amplifies with chain length and network connectivity.","Protocol-level consent and privacy controls, which the paper lists as a future direction, may be a more scalable privacy defense than per-output filtering because they would stop leakage before it occurs.","The taxonomy suggests that security review of agent communication protocols should become part of protocol standardization itself, since several named attacks are enabled by protocol features such as tool-description parsing and agent cards."],"forward_implications":["IoA deployments will need identity management built around tamper-resistant decentralized identifiers and verifiable credentials, plus context-aware access control that adjusts as agents change roles.","Chained agent workflows should assume that one agent's hallucination or poisoned output can amplify downstream, making RAG grounding, multi-agent auditing, and topology-level isolation standard practice.","Embodied agents need defense in depth spanning hardware shielding, redundant sensors, world-model simulation, and validation that language and action outputs agree.","Privacy protections should combine pre-deployment leakage assessment with runtime filtering and redaction of sensitive outputs, since inference and memorization can leak data that was never directly disclosed.","Static security rules will not be enough; the paper's lessons point to adaptive, semantically aware, real-time defenses across the whole agent lifecycle."],"supporting_citations":[{"why":"Defines the Internet of Agents as an agent-centric web, the object of the survey.","marker":"[4]"},{"why":"Introduces the Model Context Protocol, whose tool descriptions and server naming are used to illustrate impersonation and tool-poisoning attacks.","marker":"[21]"},{"why":"Introduces the A2A protocol with agent cards and authentication, the setting for Sybil and identity-related attacks.","marker":"[22]"},{"why":"Introduces the Agent Network Protocol with decentralized identifiers and end-to-end encryption, a reference point for identity-management defenses.","marker":"[23]"},{"why":"Foice supplies the identity-forgery attack that motivates authentication defenses in IoA.","marker":"[6]"},{"why":"Secret collusion via steganography is the paper's evidence for agent collusion as a cross-agent trust threat.","marker":"[8]"},{"why":"Hallucination snowballing is the basis for the hallucination-cascade threat in chained agents.","marker":"[11]"},{"why":"PoisonedRAG demonstrates knowledge poisoning of shared knowledge bases used in IoA collaboration.","marker":"[30]"},{"why":"BadRobot shows safety misalignment between language refusals and executable action plans in embodied agents.","marker":"[36]"},{"why":"RAG-Thief demonstrates extraction of private knowledge via agent-based queries, grounding the RAG privacy leakage category.","marker":"[54]"}],"fun_headline_variants":["IoA threats: identity, trust, embodied, privacy","Four attack fronts: identity, trust, embodied, privacy","Agent networks face identity, trust, embodied, privacy attacks","Survey maps four IoA security threats and defenses","Internet of Agents: four key security fronts"],"cache_read_input_tokens":3200,"weakest_assumption_plain":"The load-bearing premise is that the Internet of Agents is a genuinely new security context, so that attacks and defenses developed for single LLM agents and ordinary cyber-physical systems genuinely apply and combine there.","fun_headline_variants_meta":{"raw":{"variants":["IoA threats: identity, trust, embodied, privacy","Four attack fronts: identity, trust, embodied, privacy","Agent networks face identity, trust, embodied, privacy attacks","Survey maps four IoA security threats and defenses","Internet of Agents: four key security fronts"]},"model":"deepseek-v4-flash","effort":"low","cost_usd":0.000718,"raw_usage":{"total_tokens":3173,"prompt_tokens":839,"completion_tokens":2334,"prompt_tokens_details":{"cached_tokens":384},"prompt_cache_hit_tokens":384,"prompt_cache_miss_tokens":455,"completion_tokens_details":{"reasoning_tokens":2268}},"tokens_in":455,"tokens_out":2334,"duration_ms":15750,"temperature":1.0,"reasoning_tokens":2268,"cache_read_input_tokens":384,"cache_creation_input_tokens":0},"cache_creation_input_tokens":0},"created_at":"2026-08-15T22:22:18.996041+00:00","model_set":{"reader":"deepseek-v4-flash"},"falsifier":"A concrete disconfirmation would be a systematic audit showing that every attack in the taxonomy succeeds with equal or greater ease against a single LLM agent or an ordinary IoT device with no agent-to-agent coordination involved; that would collapse the claimed IoA-specific threat landscape into a relabeling of existing categories.","supporting_citations":[{"cited_title":"Internet of agents: Weaving a web of heterogeneous agents for collaborative intelligence,","cited_arxiv_id":null,"evidence_quote":"Defines the Internet of Agents as an agent-centric web, the object of the survey."},{"cited_title":"Model context protocol (MCP)","cited_arxiv_id":null,"evidence_quote":"Introduces the Model Context Protocol, whose tool descriptions and server naming are used to illustrate impersonation and tool-poisoning attacks."},{"cited_title":"Agent to agent protocol (A2A)","cited_arxiv_id":null,"evidence_quote":"Introduces the A2A protocol with agent cards and authentication, the setting for Sybil and identity-related attacks."},{"cited_title":"Agent network protocol (ANP)","cited_arxiv_id":null,"evidence_quote":"Introduces the Agent Network Protocol with decentralized identifiers and end-to-end encryption, a reference point for identity-management defenses."},{"cited_title":"Can i hear your face? pervasive attack on voice authentication systems with a single face image,","cited_arxiv_id":null,"evidence_quote":"Foice supplies the identity-forgery attack that motivates authentication defenses in IoA."},{"cited_title":"Secret collusion among ai agents: Multi-agent deception via steganography,","cited_arxiv_id":null,"evidence_quote":"Secret collusion via steganography is the paper's evidence for agent collusion as a cross-agent trust threat."},{"cited_title":"How language model hallucinations can snowball,","cited_arxiv_id":null,"evidence_quote":"Hallucination snowballing is the basis for the hallucination-cascade threat in chained agents."},{"cited_title":"MCP security notification: Tool poisoning attacks","cited_arxiv_id":null,"evidence_quote":"PoisonedRAG demonstrates knowledge poisoning of shared knowledge bases used in IoA collaboration."},{"cited_title":"Retrieval-augmented generation for knowledge-intensive NLP tasks,","cited_arxiv_id":null,"evidence_quote":"BadRobot shows safety misalignment between language refusals and executable action plans in embodied agents."},{"cited_title":"Language models meet world models: embodied experiences enhance language models,","cited_arxiv_id":null,"evidence_quote":"RAG-Thief demonstrates extraction of private knowledge via agent-based queries, grounding the RAG privacy leakage category."}],"review_version":1}