August 2026Unreviewed
Whispers of Wealth: A Systematic Red-Teaming Study of the Agent Payments Protocol (AP2)
Tanusree Debi, Wentian Zhu
2026 International Conference on Intelligent Multimedia, Networking, and Security (IMNS)
Abstract
Large language model (LLM)-based agents are increasingly used to automate financial transactions, but their reliance on contextual reasoning introduces new security risks. The Agent Payments Protocol (AP2) secures agent-mediated purchases through cryptographically signed mandates; however, its robustness against reasoning-layer attacks remains unclear. This paper presents a systematic red-teaming evaluation of AP2 and identifies vulnerabilities arising from prompt injection. Two attack technique
Categories
Framework mappings
OWASP Top 10 for LLM Applications
- LLM01Prompt Injection
MITRE ATLAS
- AML.T0051LLM Prompt Injection
NIST AI Risk Management Framework
- MEASUREMeasure
Suggested from the entry's categories.
Cite
@inproceedings{debi2026whispers,
title = {{Whispers of Wealth: A Systematic Red-Teaming Study of the Agent Payments Protocol (AP2)}},
author = {Tanusree Debi and Wentian Zhu},
year = {2026},
month = aug,
booktitle = {2026 International Conference on Intelligent Multimedia, Networking, and Security (IMNS)},
doi = {10.1109/IMNS67862.2026.11655291},
url = {https://www.semanticscholar.org/paper/ad5348c7ef25e740afae709cb6bd799d38b5d7ab}
}