Google and Meta Researchers: AI Agent Security Is a Systems Problem, Not a Model Problem

Google and Meta Researchers: AI Agent Security Is a Systems Problem, Not a Model Problem

N
News Editor 01
2026-07-24 04:30:16
Researchers from Google, Meta, and academia publish a paper arguing AI agent security should be addressed at the system level rather than solely by improving model capabilities. Three key mechanisms are proposed, highlighted by the recent Bankr attack.

A joint paper titled Agent Security is a Systems Problem, revised on May 20, was published by researchers from Google, Meta's Gray Swan AI, EmbraceTheRed, and multiple universities. After analyzing various attack cases, the team argues that the industry's prevailing approach—making models more robust—is insufficient. Instead, they advocate leveraging decades-proven computer security principles.

Core Argument: Model Robustness Is Not Enough

The researchers state: "Efforts to improve model robustness are important but alone cannot solve the problem. We must supplement them with systems security techniques." They model agent security as an instance of computer security, which has long dealt with powerful adversaries and developed principles to counter them.

Three Defense Mechanisms

First, separate instructions from untrusted data. Many attacks happen when agents mix instructions and data from the same source, allowing malicious commands hidden in the data to mislead the agent.

Second, enforce the principle of least privilege. Agents should not have full access rights by default; each task (e.g., checking balance vs. executing a trade) should use a specific permission level.

Third, control the flow of sensitive information. The system, not the agent, should decide where data can be sent, preventing leaks to unsafe destinations.

Real-World Case: Bankr Attack

On the same day as the paper's release, AI crypto trading assistant Bankr halted trading after at least 14 wallets were compromised. Aaron Ratcliff, Head of Attribution at Merkle Science, previously warned that giving AI agents wallet access introduces a trust layer in a trustless system. "It's only safe if the system is correctly designed," he said. Ratcliff noted agents must be capable of front-running detection, slippage limits, scam token identification, real-time contract auditing, and prompt sandboxing.

Explosive Growth Ahead

Circle CEO Jeremy Allaire predicted billions of AI agents executing tasks within five years. Agents already build Web3 apps, issue tokens, and interact autonomously with protocols. Solana's recent AI hackathon featured 12 agent projects. Sean Ren, co-founder of Sahara AI, called well-configured Model Context Protocol (MCP) a "gold standard" but stressed users must monitor every agent action. "MCP acts as a gatekeeper between the AI model and your wallet," Ren said. "The agent can only perform specific, approved actions like checking balance or preparing payment for confirmation—not freely move funds."

Market Implications

With agents set to multiply exponentially, system-level security design will determine crypto market stability. The key takeaway: security is not about making models stronger, but about building a more complete system architecture.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
400

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.