Securing Agent-to-Agent Communication in Generative AI Systems

The project “Securing Agent-to-Agent Communication in Generative AI Systems” addresses the growing risks in multi-agent environments where autonomous AI systems collaborate to complete tasks. As Generative AI evolves beyond single models into networks of cooperating agents, new threats emerge, including cross-agent hallucinations, covert coordination, unsafe delegation of authority, and leakage of sensitive data. These risks are not adequately mitigated by existing cybersecurity practices, making this an urgent area of study.

This project will design, implement, and evaluate mechanisms to secure agent-to-agent interactions. Proposed solutions include encrypted communication channels, digital signatures to verify authenticity, and role-based access control to ensure agents only operate within defined privileges. In addition, monitoring and anomaly detection will be applied to identify abnormal coordination or misuse of delegated actions.

Students will develop proof-of-concept demonstrations, such as agents exchanging signed and encrypted messages, and a sandboxed multi-agent workflow with restricted permissions and full logging. The deliverables will include a technical framework mapping threats to mitigations, PoC prototypes, and educational resources to guide responsible adoption of secure multi-agent AI systems. By extending established security principles such as those in OWASP to the emerging world of AI agents, this project provides both academic value and immediate practical relevance.

Objectives


The objective of this project is to identify risks in multi agent AI systems and design practical mechanisms that secure communication between agents. The work will integrate research, protocol design, and proof of concept demonstrations.

  1. Identify Threats
    Analyze common risks in agent to agent ecosystems such as prompt manipulation, cross agent hallucinations, covert coordination, and unsafe delegation. Document scenarios where these threats could occur in real world applications like chatbots, workflow automation, or AI powered assistants.
  2. Design Mitigation Mechanisms
    Develop security controls that address identified risks. Examples include encryption for secure message exchange, digital signatures for verifying authenticity, role based access control to limit privileges, and monitoring with anomaly detection to identify unusual coordination patterns.
  3. Proof of Concept Demonstrations
    Implement at least two working demonstrations:
    1. PoC 1: Two agents exchanging signed and encrypted messages to ensure confidentiality and authenticity.
    2. PoC 2: A small multi agent workflow sandboxed with whitelisted actions, restricted permissions, and full logging to detect and prevent unsafe behavior.
  4. Framework Development
    Produce a framework that maps agent to agent threats to mitigation strategies, modeled after approaches such as OWASP. Include diagrams, design blueprints, and technical guidance for secure implementation.
  5. Final Deliverables
    Deliverables will include a technical report with risk analysis and mitigation designs, proof of concept implementations, and educational resources that explain how to apply secure communication principles to agent ecosystems.

Motivations


Generative AI is rapidly shifting from single model applications to ecosystems of autonomous agents that collaborate to complete complex tasks. These multi agent systems bring powerful new capabilities but also introduce unique risks that traditional security models were not designed to handle. Agents can unintentionally share sensitive data, delegate unsafe actions, or reinforce each other’s hallucinations, leading to outcomes that are unpredictable and potentially harmful. Covert coordination between agents could also allow malicious behaviors to go undetected.

Currently, there are few established frameworks to secure agent to agent communication, making this a critical research and engineering gap. By addressing this challenge, the project not only contributes to the safety and trustworthiness of AI systems but also equips students to anticipate and mitigate risks in next generation technologies. The motivation is to develop practical mechanisms such as encryption, message verification, role based controls, and monitoring that ensure agents interact in a way that is safe, explainable, and aligned with human intentions. This aligns directly with the capstone initiative’s goal of applying academic knowledge to emerging real world challenges with high societal impact.

Qualifications


Minimum Qualifications:

Students should have a basic understanding of computer science principles and programming skills in at least one high level language such as Python or Java. Familiarity with concepts in computer networking or distributed systems is required, since the project focuses on secure communication between agents. A foundational knowledge of cybersecurity, including common vulnerabilities and authentication methods, will be helpful.

In addition, students should be able to research academic and industry sources, think critically about technical risks, and document findings in a clear manner. The project also requires teamwork skills and the ability to design and test small scale proof of concept implementations.

Preferred Qualifications:

Students with prior experience in artificial intelligence, machine learning, or working with Generative AI frameworks such as OpenAI, Hugging Face, or LangChain will be well suited for this project. Familiarity with basic cryptography concepts such as encryption and digital signatures will provide an advantage when implementing secure communication channels.

Knowledge of cybersecurity frameworks like OWASP or NIST, as well as experience with access control models such as role based access control, will strengthen the project outcomes. Exposure to cloud platforms, containerization technologies like Docker or Kubernetes, or logging and monitoring tools will also be beneficial. Strong collaboration skills, along with an interest in ethical AI and responsible technology adoption, will make candidates especially effective for this initiative.


Details


Project Partner:

Rakesh Keshava

NDA/IPA:

No Agreement Required

Number Groups:

1

Project Status:

Accepting Applicants

Card Image Capstone