Skip to content
Search
paperMay 2026Unreviewed

When Agents Handle Secrets: A Survey of Confidential Computing for Agentic AI

Javad Forough, Marios Kogias, Hamed Haddadi

Abstract

Agentic AI systems, specifically LLM-driven agents that plan, invoke tools, maintain persistent memory, and delegate tasks to peer agents via protocols such as MCP and A2A, introduce a threat surface that differs materially from standalone model inference. Agents accumulate sensitive context, hold credentials, and operate across pipelines no single party fully controls, enabling prompt injection, context exfiltration, credential theft, and inter-agent message poisoning. Current defenses operate

Categories

Framework mappings

MITRE ATLAS
  • AML.T0051LLM Prompt Injection

Suggested from the entry's categories.

Cite

@misc{forough2026when,
  title = {{When Agents Handle Secrets: A Survey of Confidential Computing for Agentic AI}},
  author = {Javad Forough and Marios Kogias and Hamed Haddadi},
  year = {2026},
  month = may,
  eprint = {2605.03213},
  archivePrefix = {arXiv},
  url = {https://arxiv.org/abs/2605.03213}
}