A formal model of agentic AI vulnerabilities in containerised cloud environments
Abstract
In today’s evolving digital landscape, a new kind of AI has emerged: agentic artificial intelligence (AI) systems. These are not just tools but intelligent entities that act on their own, make decisions, and carry out tasks proactively. Once placed inside containerised cloud environments such as Kubernetes, however, these powerful agents open the door to a whole new category of security concerns. They often interact on the fly with application programming interfaces, data channels, and other AI agents, sometimes all at once, and not always in predictable ways. Recognising the risks, this paper introduces a formal framework designed to capture and analyse these unique vulnerabilities. Going beyond theory, the study offers a full threat taxonomy focused on agent behaviours, uses temporal logic to trace how agents and environments interact over time, and introduces a practical measure called the Agentic Vulnerability Exposure Metric (AVEM). To put this model to the test, researchers ran simulated cyberattacks on a Kubernetes-based orchestration system that was managing large language model (LLM)-powered agents. The results were eye-opening: AVEM was able to expose security holes such as weak isolation between agents, overlooked permissions, and routes for privilege escalation that had gone undetected before. To test the practicality of the model, real-world attack scenarios are simulated on a Kubernetes-managed AI platform utilising LLM agents. The findings reveal that AVEM effectively uncovers weaknesses such as poorly defined isolation boundaries, unexpected capabilities, and opportunities for privilege escalation between agents. This article is also included in The Business & Management Collection which can be accessed at https://hstalks.com/business/.
The full article is available to subscribers to the journal.
Author's Biography
Advait Patel is a Senior Site Reliability Engineer and Cloud Security professional at Broadcom, experienced in cloud infrastructure, DevSecOps, and secure software-as-a-service platform engineering across Amazon Web Service and Google Cloud. His work focuses on cloud security, zero trust architectures, compliance automation, and resilient large-scale distributed systems. He is the creator of DockSec, an Open Worldwide Application Security Project (OWASP)-adopted AI-powered Docker security analyser, and a founding member of the OWASP AI Vulnerability Scoring System project. Advait is an active contributor to the cyber security and cloud community through speaking engagements, peer review, and technical leadership, and he has authored and edited multiple books with Springer Nature and Wiley on Google Cloud security, identity access management, and emerging artificial intelligence security topics.
Vaishnavi Gudur is a Senior Software Engineer at Microsoft, where she architects secure and scalable systems that safeguard more than 145 million Microsoft Teams users worldwide. Her work focuses on phishing protection, compliance, and artificial intelligence (AI)-driven security, blending deep technical expertise with a commitment to responsible innovation. Beyond her engineering role, Vaishnavi is an active researcher and thought leader in AI governance and ethical AI. She has published on topics including privacy-sensitive smart contracts, zero-day cyber threat detection, and trustworthy AI architectures. As a recognised voice in the field, Vaishnavi has delivered invited talks at leading industry and academic forums, including SecurityWeek’s AI Risk Summit, IEEE Cloud Computing Symposium, and NDC, Open Worldwide Application Security Project chapters where she highlights the real-world risks of deploying AI in enterprise environments and offers practical frameworks for building resilient, ethical systems. She also serves as a peer reviewer for IEEE and as a lead editor with Springer Nature, helping shape the next generation of scholarship in AI ethics and cyber security. Passionate about bridging research, engineering, and governance, Vaishnavi is building a global platform to advance safe, transparent, human-centred AI adoption at scale.
Charit Upadhyay is an experienced Senior Site Reliability Engineer with more than 8 years’ expertise in designing, deploying, and maintaining large-scale, highly available systems. He has a proven track record of leading cross-functional teams, driving strategic initiatives, and enhancing system reliability and performance.
Shalini Sudarsan is a DevOps Engineering Leader at KinderCare Learning Companies, USA. She designs reliable, secure, cost-optimised data and artificial intelligence (AI) platforms. A Forbes Technology Council Member, Shalini is also a Fellow of the Institution of Electronics and Telecommunication Engineers and the IEEE Women in Engineering vice-chair. She drives enterprise AI adoption through a governed operating model that accelerates time-to-market while reducing risk and spend. Shalini’s expertise spans business intelligence strategy, data platform architecture, machine learning operations, observability, and value realisation. She is known for translating complex engineering into measurable business outcomes. Shalini brings deep technical rigour and business expertise in DevOps and reliability engineering. A committed advocate for advancing technology, Shalini regularly presents at international conferences, is an author and editor with Springer Nature, and contributes to IEEE and ACM as a technical reviewer.