为自主智能体设计可控制的安防架构,保障跨系统协作安全
SAGA: A Security Architecture for Governing AI Agentic Systems
- 通过中心化注册与加密令牌机制实现用户对智能体全生命周期管控
- 在多地理分布、混合云端设备环境下测试,性能开销极低且任务效果无损
- 适合需高安全性部署的金融、医疗等敏感场景使用
基于大语言模型的智能体正日益实现自主交互、协作与任务委派,减少人工干预。行业指南强调用户必须全面掌控自身智能体,以防范恶意行为带来的损害。现有设计方案虽涵盖身份认证、授权与委托,但多为理论构想,缺乏实际实现与评估,尤其缺少用户可控的管理能力。为此,我们提出SAGA——一种可扩展的智能体治理安全架构,支持用户对智能体生命周期的监督。用户将智能体注册至中央机构(Provider),该机构维护智能体联系方式、用户定义的访问控制策略,并协助智能体在跨智能体通信中执行策略。我们引入一种密码学机制,用于生成细粒度访问控制令牌,提供形式化安全保证。我们在多种智能体任务上评估SAGA,涵盖不同地理位置的智能体及多种本地与云端LLM,结果表明其性能开销极小,且不影响任务实用性。该架构可实现安全可信的自主智能体部署,推动技术在敏感环境中的负责任应用。
原文摘要 · Abstract (English)
Large Language Model (LLM)-based agents increasingly interact, collaborate, and delegate tasks to one another autonomously with minimal human interaction. Industry guidelines for agentic system governance emphasize the need for users to maintain comprehensive control over their agents, mitigating potential damage from malicious agents. Several proposed agentic system designs address agent identity, authorization, and delegation, but remain purely theoretical, without concrete implementation and evaluation. Most importantly, they do not provide user-controlled agent management. To address this gap, we propose SAGA, a scalable Security Architecture for Governing Agentic systems, that offers user oversight over their agents' lifecycle. In our design, users register their agents with a central entity, the Provider, that maintains agent contact information, user-defined access control policies, and helps agents enforce these policies on inter-agent communication. We introduce a cryptographic mechanism for deriving access control tokens, that offers fine-grained control over an agent's interaction with other agents, providing formal security guarantees. We evaluate SAGA on several agentic tasks, using agents in different geolocations, and multiple on-device and cloud LLMs, demonstrating minimal performance overhead with no impact on underlying task utility in a wide range of conditions. Our architecture enables secure and trustworthy deployment of autonomous agents, accelerating the responsible adoption of this technology in sensitive environments.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。