Security Analysis of Agentic AI Communication Protocols: A Comparative Evaluation
Yedidel Louck, Ariel Stulman, Amit Dvir

TL;DR
This paper conducts a comprehensive security evaluation of two agent communication protocols, revealing strengths and vulnerabilities, and proposes a hybrid approach to enhance security in multi-agent AI systems.
Contribution
It provides the first empirical comparison of CORAL and ACP security protocols, identifying specific architectural strengths and implementation weaknesses.
Findings
CORAL has strong transport-layer validation but critical implementation vulnerabilities.
ACP's flexibility leads to significant integrity and confidentiality flaws.
Existing protocols are currently insufficiently secure for practical deployment.
Abstract
Multi-agent systems (MAS) powered by artificial intelligence (AI) are increasingly foundational to complex, distributed workflows. Yet, the security of their underlying communication protocols remains critically under-examined. This paper presents the first empirical, comparative security analysis of the official CORAL implementation and a high-fidelity, SDK-based ACP implementation, benchmarked against a literature-based evaluation of A2A. Using a 14 point vulnerability taxonomy, we systematically assess their defenses across authentication, authorization, integrity, confidentiality, and availability. Our results reveal a pronounced security dichotomy: CORAL exhibits a robust architectural design, particularly in its transport-layer message validation and session isolation, but suffers from critical implementation-level vulnerabilities, including authentication and authorization…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsMobile Agent-Based Network Management · Advanced Authentication Protocols Security · Security and Verification in Computing
