Published September 3, 2026 | Version v1

Meet-Oracle Scope Inference: A Membership-Query Side Channel in Intersection-Based Multi-Agent Authorization

Authors/Creators

Description

Multi-agent authorization protocols increasingly compose separately issued grants by set intersection, because intersection can only narrow authority. This paper shows that the same property turns a correctly functioning verifier into a perfect membership-query oracle. An attacker holding a verifier-trusted grant that covers a given tag reads one bit of a victim's confidential scope with a single call on that tag. A finite, public action vocabulary bounds how many calls it takes to disclose the victim's entire scope, once the attacker's grant covers the whole vocabulary. We call this mechanism the meet-oracle and pin it exhaustively at the code level with a permanent regression test. An unmodified, general-purpose LLM agent, given only tool access and a task, carries out the extraction strategy end to end on its own. Nine of nine trials reconstruct a hidden victim scope exactly over the Model Context Protocol (MCP), reproduced identically by three attacker models; nine of nine reconstruct exactly again at a structurally different enforcement point, the Agent2Agent protocol (A2A), against real cross-process peers. Every probe in the attack is an individually legitimate, correctly authorized or denied action, so it leaves no crash or timing signature for a monitor tuned to conventional anomalies to catch. We argue, but do not test against a second real system, that the vulnerable shape, strict-intersection composition plus a per-action binary decision, is structural rather than specific to one implementation.

Files

main.pdf

Files (280.5 kB)

Name Size Download all
md5:409d86915e4e00066ba107d42f3366b0
280.5 kB Preview Download