统一安全防护框架,让一个护栏管住多种隐私计算技术
Can One Safety Loop Guard Them All? Agentic Guard Rails for Federated Computing
- 用插件化语言和控制平面实现跨隐私技术的安全管控
- 支持加密与差分隐私等多后端无缝集成,确保风险可控
- 适合隐私计算系统开发者与安全审计人员参考
我们提出Guardian-FC,一种用于保护隐私的联邦计算新型双层框架,统一管理多种隐私保护机制的安全性,包括全同态加密(FHE)、多方计算(MPC)等密码学后端,以及差分隐私(DP)等统计方法。该框架通过执行插件(模块化计算单元)将安全护栏与隐私机制解耦,插件采用专为联邦计算工作流设计的、与后端无关的领域特定语言(DSL),并可由不同执行提供者(EPs)实现,以适配各类隐私后端。一个基于签名遥测与命令的智能体控制平面,通过有限状态安全循环,实现一致的风险管理与可审计性。基于清单的设计支持快速失败的任务准入,并可无缝扩展至新隐私后端。我们展示了后端无关安全的定性场景,并建立了形式化模型基础以支持验证。最后,我们提出研究议程,呼吁社区推进自适应护栏调优、多后端组合、DSL规范开发、实现与编译器扩展,以及人机覆盖可用性。
原文摘要 · Abstract (English)
We propose Guardian-FC, a novel two-layer framework for privacy preserving federated computing that unifies safety enforcement across diverse privacy preserving mechanisms, including cryptographic back-ends like fully homomorphic encryption (FHE) and multiparty computation (MPC), as well as statistical techniques such as differential privacy (DP). Guardian-FC decouples guard-rails from privacy mechanisms by executing plug-ins (modular computation units), written in a backend-neutral, domain-specific language (DSL) designed specifically for federated computing workflows and interchangeable Execution Providers (EPs), which implement DSL operations for various privacy back-ends. An Agentic-AI control plane enforces a finite-state safety loop through signed telemetry and commands, ensuring consistent risk management and auditability. The manifest-centric design supports fail-fast job admission and seamless extensibility to new privacy back-ends. We present qualitative scenarios illustrating backend-agnostic safety and a formal model foundation for verification. Finally, we outline a research agenda inviting the community to advance adaptive guard-rail tuning, multi-backend composition, DSL specification development, implementation, and compiler extensibility alongside human-override usability.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。