Runtime Authority-Aware Threat Modeling for Agentic AI Systems: A Framework for Intent, Tool, Memory, and Delegation Risk
DOI:
https://doi.org/10.70589/JRTCSE.2026.14.4.2Keywords:
Agentic AI Security, AI Agents, Threat Modeling, Runtime Security, Prompt Injection, Authorization, Tool Security, Memory Poisoning, Multi-Agent Systems, Least PrivilegeAbstract
Enterprise AI agents increasingly retrieve external content, select tools, invoke APIs, retain memory, delegate work, and compose multi-step actions. These capabilities complicate conventional threat modeling because security consequences depend not only on where data flows, but also on what can influence agent decisions and what authority those decisions can exercise. This paper proposes the Authority-Aware Agentic Threat Model (AATM), a structured review overlay organized around seven dimensions: intent, context, authority, tool capability, memory, delegation, and action composition. AATM adds authority surface, influence flow, and authority graph artifacts to established architecture analysis. Six representative scenarios and a worked enterprise case study are examined using a clearly defined Explicit/Derived/Absent rubric. The analysis is scenario-based and single-analyst; it does not claim empirical superiority over STRIDE or other established methods. Instead, it shows how AATM makes task-authority mismatch, transitive privilege, persistent influence, and sequence-dependent risk explicit in review artifacts. The resulting design guidance emphasizes task-scoped credentials, narrow semantic tools, provenance-aware memory, independent runtime authorization, delegation constraints, and sequence-aware policy. AATM is intended as a practical architectural lens for agent systems whose execution paths are partly determined at runtime.
References
J. H. Saltzer and M. D. Schroeder, “The Protection of Information in Computer Systems,” Proceedings of the IEEE, vol. 63, no. 9, pp. 1278–1308, 1975. https://doi.org/10.1109/PROC.1975.9939
S. Rose, O. Borchert, S. Mitchell, and S. Connelly, “Zero Trust Architecture,” NIST Special Publication 800-207, 2020. https://doi.org/10.6028/NIST.SP.800-207
E. Tabassi, “Artificial Intelligence Risk Management Framework (AI RMF 1.0),” NIST AI 100-1, 2023. https://doi.org/10.6028/NIST.AI.100-1
C. Autio et al., “Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile,” NIST AI 600-1, 2024. https://doi.org/10.6028/NIST.AI.600-1
Q. Zhan, Z. Liang, Z. Ying, and D. Kang, “InjecAgent: Benchmarking Indirect Prompt Injections in Tool-Integrated Large Language Model Agents,” Findings of ACL 2024, pp. 10471–10506. https://aclanthology.org/2024.findings-acl.624/
E. Debenedetti, J. Zhang, M. Balunovic, L. Beurer-Kellner, M. Fischer, and F. Tramer, “AgentDojo: A Dynamic Environment to Evaluate Prompt Injection Attacks and Defenses for LLM Agents,” 2024. https://arxiv.org/abs/2406.13352
E. Debenedetti et al., “Defeating Prompt Injections by Design,” 2025. https://arxiv.org/abs/2503.18813
OWASP GenAI Security Project, “OWASP Top 10 for Agentic Applications for 2026,” 2025. https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/
MITRE, “ATLAS: Adversarial Threat Landscape for Artificial-Intelligence Systems.” https://atlas.mitre.org/
Model Context Protocol, “Authorization Specification.” https://modelcontextprotocol.io/specification/2025-06-18/basic/authorization
Model Context Protocol, “Security Best Practices.” https://modelcontextprotocol.io/docs/tutorials/security/security_best_practices
Model Context Protocol, “Understanding Authorization in MCP.” https://modelcontextprotocol.io/docs/tutorials/security/authorization.
Downloads
Issue
Section
License
Copyright (c) 2026 Ravindra Annam Journal (Author)

This work is licensed under a Creative Commons Attribution-NonCommercial 4.0 International License.




