Research · curated 4 Oct 2026

From A2A Attacks to Envelope-Layer Defense: Red-Teaming Evaluation of LLM Agents and a Three-Layer Isomorphic Attack–Defense Model

Coverage timeline

4 Oct 2026arxiv.orgprimary

Single-source research — first reported, latest, and curated coincide.

Why it matters

Multi-agent protocols like A2A treat peer task requests as legitimate, opening a natural channel for indirect prompt injection and exfiltration that single-agent security evaluations fail to detect, and this work identifies the envelope layer as a new defense dimension defenders must harden.

A research paper introduces A2A-TIBA, an attack combining indirect prompt injection with bypass circumvention against LLM agents communicating over Agent-to-Agent (A2A) and ACP protocols, using implant–command–exfiltration steps to deploy a callback program and issue commands bypassing the agent layer. The authors also propose GDA Measurement (a red-team testbed with LLM-gateway context capture and agent-based judging), an extended taxonomy of four attack outcomes, and ELA-ITL, a three-layer isomorphic attack–defense model, validated across 15 agent front-end × LLM back-end combinations and a 1,000-case dataset.