arXiv · 2609.33924
A2A-ForensicTrace: Offline Verification of Tamper-Evident A2A Runtime Evidence
Abstract
Security-relevant Agent2Agent (A2A) executions can cross organizational boundaries, leaving investigators without live access to all participating systems. Offline investigation involves checking preserved records and their cross-record relationships for consistency. This paper presents A2A-ForensicTrace, an offline verification layer that converts runtime observations into typed records, derives protocol-relevant relationships, and commits both under an incident-trace root. An Ed25519-signed receipt binds the root and capture digest to the incident context. Evaluation comprised 240 executions through the official A2A software development kit (SDK), with actions selected by a large language model (LLM). These included 120 condition runs and 120 matched controls. All condition runs returned the expected bounded findings. No control produced an indication, and all roots and receipts verified. Median in-memory latency of the full offline verifier was 1.61 ms for the scenario traces. In the separate scaling experiment, it was 30.85 ms at 1,000 committed leaves. Future work will broaden A2A lifecycle coverage.
Explore related subjects
Keep this discovery
Explore connections, maps & timelines
Adil Alshammari, Sareh Assiri, Hayretdin Bahsi. 2026-09-27. A2A-ForensicTrace: Offline Verification of Tamper-Evident A2A Runtime Evidence. https://arxiv.org/abs/2609.33924
Cite the original work for its findings. Save a collection to share your selection of sources.