Research · curated 4 Oct 2026
From A2A Attacks to Envelope-Layer Defense: Red-Teaming Evaluation of LLM Agents and a Three-Layer Isomorphic Attack–Defense Model
First reported arxiv.org
Coverage timeline
Single-source research — first reported, latest, and curated coincide.
Why it matters
Multi-agent protocols like A2A treat peer task requests as legitimate, opening a natural channel for indirect prompt injection and exfiltration that single-agent security evaluations fail to detect, and this work identifies the envelope layer as a new defense dimension defenders must harden.
A research paper introduces A2A-TIBA, an attack combining indirect prompt injection with bypass circumvention against LLM agents communicating over Agent-to-Agent (A2A) and ACP protocols, using implant–command–exfiltration steps to deploy a callback program and issue commands bypassing the agent layer. The authors also propose GDA Measurement (a red-team testbed with LLM-gateway context capture and agent-based judging), an extended taxonomy of four attack outcomes, and ELA-ITL, a three-layer isomorphic attack–defense model, validated across 15 agent front-end × LLM back-end combinations and a 1,000-case dataset.