Blockchain Empowered Trustworthy Agent Networks: Foundations, Taxonomy, and Future Directions
2026/08/05 by Liehuang Zhu, Yuhang Li, Tianxing Wang +7
Computer Science · #cs.CR
paper · pdf
arxiv created 2026/08/05 · arxiv updated 2026/08/06
Abstract
AI agents are evolving from isolated task executors into networked autonomous entities that can communicate, delegate tasks, invoke tools, access external knowledge, and participate in cross-platform service and economic workflows. This evolution gives rise to open agent networks, where heterogeneous agents owned by different stakeholders interact without naturally shared infrastructures for identity, authorization, auditability, reputation, or settlement. This survey and tutorial article reviews the literature over the period 1980--2026 on the evolution from classical multi-agent systems to open agent networks, with a particular focus on LLM-based autonomous agents, agent interoperability protocols, Internet-of-Agents infrastructures, and blockchain-enabled trust mechanisms. We first review this evolution and show how the trust boundary expands from individual execution to cross-agent, cross-platform, and cross-organizational interaction. We then identify a network-level trust crisis that cannot be fully addressed by single-agent safety mechanisms or closed multi-agent coordination techniques, and develop a five-dimensional taxonomy covering entity and capability trust, authorization and delegation trust, information and provenance trust, coordination and group-robustness trust, and accountability and settlement trust. Based on this taxonomy, we examine how blockchain can provide shared identity, verifiable authorization, tamper-evident provenance, auditable collaboration, incentive alignment, and value settlement for trustworthy agent networks. We further synthesize the mapping between agent-network risks, trust requirements, and blockchain-enabled mechanisms, and clarify the role of blockchain as a shared trust layer rather than a replacement for agent security, semantic verification, privacy protection, or robust reasoning.
Citations
- SoK: Security of Autonomous LLM Agents in Agentic Commerce
- SoK: Blockchain Agent-to-Agent Payments
- Benchmarking LLM Tool-Use in the Wild
- Security Threat Modeling for Emerging AI-Agent Protocols: A Comparative Analysis of MCP, A2A, Agora, and ANP
- Overcoming the Retrieval Barrier: Indirect Prompt Injection in the Wild for LLM Systems
- DAO-Agent: Zero Knowledge-Verified Incentives for Decentralized Multi-Agent Coordination
- A Blockchain-Monitored Agentic AI Architecture for Trusted Perception-Reasoning-Action Pipelines
- Binding Agent ID: Unleashing the Power of AI Agents with accountability and credibility
- Insured Agents: A Decentralized Trust Insurance Mechanism for Agentic Economy
- Toward a Safe Internet of Agents
- Inter-Agent Trust Models: A Comparative Study of Brief, Claim, Proof, Stake, Reputation and Constraint in Agentic Web Protocol Design-A2A, AP2, ERC-8004, and Beyond
- Agentic AI Security: Threats, Defenses, Evaluation, and Open Challenges
- MCP Security Bench (MSB): Benchmarking Attacks Against Model Context Protocol in LLM Agents
- Decentralized Multi-Agent System with Trust-Aware Communication
- Towards Transparent and Incentive-Compatible Collaboration in Decentralized LLM Multi-Agent Systems: A Blockchain-Driven Approach
- SoK: Security and Privacy of AI Agents for Blockchain
- BetaWeb: Towards a Blockchain-enabled Trustworthy Agentic Web
- BlockA2A: Towards Secure and Verifiable Agent-to-Agent Interoperability
- Byzantine-Robust Decentralized Coordination of LLM Agents
- Agent Network Protocol Technical White Paper
- The Trust Fabric: Decentralized Interoperability and Economic Coordination for the Agentic Web
- MOD-X: A Modular Open Decentralized eXchange Framework proposal for Heterogeneous Interoperable Artificial Intelligence Agents
- Agent Exchange: Shaping the Future of AI Agent Economics
- A Survey on Autonomy-Induced Security Risks in Large Model-Based Agents
- From Prompt Injections to Protocol Exploits: Threats in LLM-Powered AI Agents Workflows
- A Survey of LLM-Driven AI Agent Communication: Protocols, Security Risks, and Defense Countermeasures
- Agent Name Service (ANS): A Universal Directory for Secure AI Agent Discovery and Interoperability
- Internet of Agents: Fundamentals, Applications, and Challenges
- Security of Internet of Agents: Attacks and Countermeasures
- A Weighted Byzantine Fault Tolerance Consensus Driven Trusted Multiple Large Language Models Network
- A survey of agent interoperability protocols: Model Context Protocol (MCP), Agent Communication Protocol (ACP), Agent-to-Agent Protocol (A2A), and Agent Network Protocol (ANP)
- Open Challenges in Multi-Agent Security: Towards Secure Systems of Interacting AI Agents
- ACE: A Security Architecture for LLM-Integrated App Systems
- Prompt Injection Attack to Tool Selection in LLM Agents
- Traceback of Poisoning Attacks to Retrieval-Augmented Generation
- Inherent and emergent liability issues in LLM-based agentic systems: a principal-agent perspective
- Agents Under Siege: Breaking Pragmatic Multi-Agent LLM Systems with Optimized Prompt Attacks
- A Survey on Trustworthy LLM Agents: Threats and Countermeasures
- MultiAgentBench: Evaluating the Collaboration and Competition of LLM agents
- Leveraging Large Language Models for Effective and Explainable Multi-Agent Credit Assignment
- Red-Teaming LLM Multi-Agent Systems via Communication Attacks
- G-Safeguard: A Topology-Guided Security Lens and Treatment on LLM-based Multi-agent Systems
- Bottom-Up Reputation Promotes Cooperation with Multi-Agent Reinforcement Learning
- Agent TCP/IP: An Agent-to-Agent Transaction System
- A Survey on LLM-based Multi-Agent System: Recent Advances and New Frontiers in Application
- The Task Shield: Enforcing Task Alignment to Defend Against Indirect Prompt Injection in LLM Agents
- Navigating the Risks: A Survey of Security, Privacy, and Ethics Threats in LLM-Based Agents
- AgentOps: Enabling Observability of LLM Agents
- Agent Security Bench (ASB): Formalizing and Benchmarking Attacks and Defenses in LLM-based Agents
- ConfusedPilot: Confused Deputy Risks in RAG-based LLMs
- LLMmap: Fingerprinting For Large Language Models
- AgentPoison: Red-teaming LLM Agents via Poisoning Memory or Knowledge Bases
- ShortcutsBench: A Large-Scale Real-world Benchmark for API-based Agents
- Scaling Large Language Model-based Multi-Agent Collaboration
- Machine Against the RAG: Jamming Retrieval-Augmented Generation with Blocker Documents
- AI Agents Under Threat: A Survey of Key Security Challenges and Future Pathways
- Certifiably Robust RAG against Retrieval Corruption
- A Survey on the Memory Mechanism of Large Language Model based Agents
- InjecAgent: Benchmarking Indirect Prompt Injections in Tool-Integrated Large Language Model Agents
- Watch Out for Your Agents! Investigating Backdoor Threats to LLM-Based Agents
- PoisonedRAG: Knowledge Corruption Attacks to Retrieval-Augmented Generation of Large Language Models
- StruQ: Defending Against Prompt Injection with Structured Queries
- Large Language Model based Multi-Agents: A Survey of Progress and Challenges
- Identifying the Risks of LM Agents with an LM-Emulated Sandbox
- AgentVerse: Facilitating Multi-Agent Collaboration and Exploring Emergent Behaviors
- MetaGPT: Meta Programming for A Multi-Agent Collaborative Framework
- Counterfactually Auditable Lifecycle Certification for Autonomous Agents
- ChatDev: Communicative Agents for Software Development
- Improving Factuality and Reasoning in Language Models through Multiagent Debate
- Tree of Thoughts: Deliberate Problem Solving with Large Language Models
- Generative Agents: Interactive Simulacra of Human Behavior
- Reflexion: Language Agents with Verbal Reinforcement Learning
- Toolformer: Language Models Can Teach Themselves to Use Tools
- Distributing Accountability, Not Capability: Phase Separation and the LLM Workflow Quadrant in Autonomous AI Agent Architectures
- BNAI, NO-TOKEN, and MIND-UNITY: Pillars of a Systemic Revolution in Artificial Intelligence
- WebGPT: Browser-assisted question-answering with human feedback
- Retrieval-Augmented Generation for Knowledge-Intensive NLP Tasks
- Proximal Policy Optimization Algorithms
- Human-level control through deep reinforcement learning
- The Transport Layer Security (TLS) Protocol Version 1.3
- KQML as an agent communication language
- The Byzantine Generals Problem
- HuggingGPT: Solving AI Tasks with ChatGPT and its Friends in Hugging Face
- CAMEL: Communicative Agents for "Mind" Exploration of Large Language Model Society