14:00–14:20
| Opening Remarks
Master of Ceremony:
Naying Hu, Associate Rapporteur Question 16/17, CAICT
-
Arnaud Taddei, Chair ITU-T Study Group 17, Broadcom
-
Liang Wei, Vice Chair, ITU-T Study Group 17, CAICT
|
14:20–14:40
| Session 1: Security Risks and Attack Surface Analysis of Agentic AI This session maps the distinctive attack surface of Agentic AI — unauthorized tool and action execution, cross-agent identity spoofing, behavioral deception and goal hijacking, supply-chain poisoning, and loss of autonomous control. Using the recent OpenAI–Hugging Face security incident and other red-team findings as starting points, the session will examine how autonomous planning and self-directed execution may enable AI agents to go beyond intended boundaries, combine multiple attack steps, access external systems, and take actions that are neither anticipated nor authorized by human operators. The aim is to turn these findings into a shared, evidence-based threat picture for SG17's later work.
Format: Presentation (20 mins)
Moderator: Heung Youl Youm, Soonchunhyang University, Korea (Rep. of) Speaker: - Wei Xu, Professor at College of AI, Vice Dean of Institute for Interdisciplinary Information Sciences, Tsinghua University
Note: As moderator, Dr. Youm will give a brief introduction of frame how these lessons relate to SG17's ongoing work.
|
14:40-15:00
| Coffee Break
|
|
15:00-16:00 | Session 2: Security Mechanisms for Agentic AI This session examines security mechanisms built into the agent itself — secure-by-design architecture, policy-driven decision constraints, runtime self-inspection, chain-of-thought and behavioral monitoring, and secure update. It explores the standardization needs arising from these new situations, focusing on the gap between what Agentic AI now demands and what SG17's existing standards already cover. Format: Presentation (12 mins per speaker) Moderator: Zhiyuan Hu, vivo Mobile Communication Ltd., WP4/17 Chair
Speakers: - Xudong Pan, Associate Research Fellow, School of Computer Science, Fudan University
Topic: Securing Agentic AI Systems with AgentGuard
- Tian Tian, ZTE
Topic: Security for Agentic AI:Threats and Mitigations - Feng Gao, China Unicom | Q7/17 Rapporteur
Topic:AI-Enabled Application Security Standards: What Should We Do? - Xiaojian Li, Founder & CEO of Fangcun AI Co., Ltd.
Topic: The Agent's Own Control Plane: Decision-Time Security Enforcement and Emergent Misbehavior Evaluation
Note: As moderator, Dr. Hu will introduce SG17's existing work on AI endogenous security mechanisms.
|
16:00-17:00
| Session
3: Security
Evaluation and Verification Methods for Agentic AI
This session explores how to evaluate and verify the security of Agentic AI systems — security testing, formal verification, runtime audit and security metrics — within standardized assessment frameworks. It takes an integration-centric view: as agents are integrated into real ICT systems, evaluation must establish a verifiable baseline at the point of integration, and define what security evidence and assurances integrators should require from the suppliers of agents, tools and models.
Format: Presentation (12 mins per speaker) Moderator: Kai Wei, WP2/21 Vice-chair, CAICT
Speakers:
- Bo Liu, CAICT
Topic: Using Agents to Evaluate Agents - Xiaofang Yang, Alibaba. Inc.
Topic: From Model Spec to System Spec: Building a Verifiable Security Baseline for Agentic AI - Clement Neo, Founder & Research Lead of Neo Research
Topic: Where long-horizon agents go wrong - Yu Tang, Automated Testing Methodologies for Agentic AI via Adversarial Generation Techniques, CAERI Co., Ltd.
Topic: Agentic AI Trustworthiness Evaluation System: Establishing a Trustworthy Baseline for Intelligent Vehicle Integration
Note: As moderator, Kai will introduce SG21,SG17 and CAICT existing work on AI security evaluation.
|
17:00-17:50
| Session
4:
What Frontier Developers Can Give Us — Securing Agentic AI in Practice
This session asks whether it is affordable in practice, and brings in the frontier model developers best placed to answer. The focus is on the trade-offs that only appear once a real model ships. How much capability does security cost? Where does assurance break down at frontier scale? Which of the requirements cannot yet be met? Developers from leading frontier model enterprises will give a frank verdict on what is easy and what is hard. They will also share what they can offer the wider ecosystem, including the practices and evidence ready to be reused, and the open problems where industry still needs support.
Format: Roundtable Discussion Moderator: Debora Comparin, Thales Group | WP1/17 Chair Panellists: - Shiqi Li, Alibaba, Lead of security standardization
Talking points: Confidential computing based Agentic AI security - Dong Zhang, vivo, AI security researcher and AI governance practitioner
Talking points: On-Device Trust Control Plane for Agentic AI - Junchen Shen, MiniMax, Executive Editor
Talking points: From Perception to Permission: Preserving Goal Integrity in Multimodal, Long-Horizon Agents - Chin Ze Shen, Research Affiliate at the Oxford Martin AI Governance Initiative and a Research Analyst at the AI Standards Lab
Talking points: What common agent ID protocols do and don't address (potentially from the perspective of the OpenAI Hugging Face incident
|
17:50-18:00
| Future outlook and closing remarks- Arnaud Taddei, Chair, ITU-T Study Group 17, Broadcom
Note: SG17 Chair will draw the discussion together around what is SG17's pre-standardization and standardization roadmap, what should be carried forward to the SG17, FG-TIDA and to related work.
|