Skip to content
Search
paperMarch 2026Unreviewed

SoK: The Attack Surface of Agentic AI -- Tools, and Autonomy

Ali Dehghantanha, Sajad Homayoun

Abstract

Recent AI systems combine large language models with tools, external knowledge via retrieval-augmented generation (RAG), and even autonomous multi-agent decision loops. This agentic AI paradigm greatly expands capabilities - but also vastly enlarges the attack surface. In this systematization, we map out the trust boundaries and security risks of agentic LLM-based systems. We develop a comprehensive taxonomy of attacks spanning prompt-level injections, knowledge-base poisoning, tool/plug-in expl

Categories

Cite

@misc{dehghantanha2026sok,
  title = {{SoK: The Attack Surface of Agentic AI -- Tools, and Autonomy}},
  author = {Ali Dehghantanha and Sajad Homayoun},
  year = {2026},
  month = mar,
  eprint = {2603.22928},
  archivePrefix = {arXiv},
  url = {https://arxiv.org/abs/2603.22928}
}