🤖 AI Summary
This study addresses the challenge of offline forensics in cross-organizational agent interactions, where the absence of real-time access impedes the verification of evidence consistency and integrity. To this end, we propose an offline consistency verification mechanism that constructs a verification layer to transform runtime observations into typed records and derive protocol relationships. Tamper-evident binding is achieved through event trace root hashes and Ed25519-signed receipts. The system leverages the A2A SDK alongside large language model-driven action selection. Experimental evaluation across 240 executions demonstrates that the proposed approach accurately identifies all violations with zero false positives, achieving a median latency of merely 1.61 milliseconds for full verification while maintaining efficiency when scaled to thousands of nodes. This work effectively bridges a critical technical gap in auditing cross-boundary A2A executions.
📝 Abstract
Security-relevant Agent2Agent (A2A) executions can cross organizational boundaries, leaving investigators without live access to all participating systems. Offline investigation involves checking preserved records and their cross-record relationships for consistency. This paper presents A2A-ForensicTrace, an offline verification layer that converts runtime observations into typed records, derives protocol-relevant relationships, and commits both under an incident-trace root. An Ed25519-signed receipt binds the root and capture digest to the incident context. Evaluation comprised 240 executions through the official A2A software development kit (SDK), with actions selected by a large language model (LLM). These included 120 condition runs and 120 matched controls. All condition runs returned the expected bounded findings. No control produced an indication, and all roots and receipts verified. Median in-memory latency of the full offline verifier was 1.61 ms for the scenario traces. In the separate scaling experiment, it was 30.85 ms at 1,000 committed leaves. Future work will broaden A2A lifecycle coverage.