Sandboxing and safe execution
Isolated runtimes, capability-scoped permissions, and containment for running untrusted agents and their tool use.
Sandboxes, privacy, security, trust, and evaluation for decentralized agent networks.
“How do we make internet-scale agent networks safe, private, and trustworthy?”
AI is moving from single models toward internet-scale networks of agents that discover one another, delegate tasks, and act on our behalf over open, decentralized infrastructure. Whether such networks can be deployed responsibly is, first and foremost, a systems question: how to sandbox and contain untrusted agents, how to preserve privacy and security in agent-to-agent interaction, how to establish trust and accountability without central control, and how to evaluate all of this rigorously.
This workshop convenes the trust, privacy, and security community around the systems foundations of Networked Agents and Decentralized Architecture (NANDA). Co-located with IEEE TPS 2026 in San Jose, it focuses on the infrastructure, protocols, and evaluation needed to make agent networks trustworthy in practice. Algorithmic contributions are welcome where they serve these systems goals.
Safe execution environments and capability-scoped permissions for running untrusted agents and their tools.
Identity, authentication, and confidential, privacy-preserving protocols for agent-to-agent interaction.
Manipulation-resistant reputation, accountability, and rigorous security and privacy evaluation at scale.
We invite short papers on the trust, privacy, and security foundations of networked, decentralized agent architectures — concise systems, datasets, evaluations, and well-argued position pieces. The program spans four thrusts.
Isolated runtimes, capability-scoped permissions, and containment for running untrusted agents and their tool use.
Identity, authentication, and verifiable credentials; confidential and privacy-preserving A2A protocols; secure discovery, resolution, and routing.
Manipulation-resistant reputation, provenance and audit trails, verifiable agent metadata, and governance for decentralized networks.
Security and privacy testbeds, sandboxed evaluations, and robustness benchmarks for networked agents under adversarial and strategic pressure.
Algorithmic contributions — learned discovery, representation, or coordination — are welcome where they advance the systems, security, and evaluation goals above.
IEEE two-column conference format, including references. Concise systems, datasets, evaluations, and well-argued position pieces.
All deadlines are 23:59 anywhere on Earth (AoE). Dates are subject to change.
Tentative half-day schedule; the exact day within IEEE TPS 2026 will be announced.
| Time | Session |
|---|---|
| 00:00 – 00:10 | Opening remarks |
| 00:10 – 00:50 | Keynote |
| 00:50 – 01:35 | Contributed talks — sandboxing & secure execution |
| 01:35 – 02:00 | Coffee break |
| 02:00 – 02:45 | Contributed talks — privacy, trust & accountability |
| 02:45 – 03:15 | Contributed talks — evaluation & red-teaming |
| 03:15 – 03:55 | Panel: trust and safety for decentralized agent networks |
| 03:55 – 04:00 | Closing remarks |
MIT
MIT Media Lab
The program committee and invited speakers will be announced soon.