10
Agent Exploitation Techniques
In Chapter 9, we examined the architecture of AI agents and identified where security failures can occur. This chapter looks at how attackers exploit those weaknesses in practice.
Agents often operate through real authority, not through abstract autonomy. Sometimes they borrow a human user's permissions: a browser session, local shell, repository credential, SaaS token, or approval flow. Sometimes they run as a non-human identity with their own scoped credentials. Either way, an attacker may be able to steer the agent into using legitimate access for an unintended purpose. In a multi-agent workflow, a compromised instruction or output may also pass from one agent to another.
These attacks can be difficult to detect ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access