March 2026Unreviewed
SoK: The Attack Surface of Agentic AI -- Tools, and Autonomy
Ali Dehghantanha, Sajad Homayoun
Abstract
Recent AI systems combine large language models with tools, external knowledge via retrieval-augmented generation (RAG), and even autonomous multi-agent decision loops. This agentic AI paradigm greatly expands capabilities - but also vastly enlarges the attack surface. In this systematization, we map out the trust boundaries and security risks of agentic LLM-based systems. We develop a comprehensive taxonomy of attacks spanning prompt-level injections, knowledge-base poisoning, tool/plug-in expl
Categories
Cite
@misc{dehghantanha2026sok,
title = {{SoK: The Attack Surface of Agentic AI -- Tools, and Autonomy}},
author = {Ali Dehghantanha and Sajad Homayoun},
year = {2026},
month = mar,
eprint = {2603.22928},
archivePrefix = {arXiv},
url = {https://arxiv.org/abs/2603.22928}
}