arXiv:2508.19267cs.CRcs.AI2025-08被引 10

为自主智能体设计安全框架,防劫持、防崩溃,保障开放生态可信运行。

The Aegis Protocol: A Foundational Security Framework for Autonomous AI Agents

  • 用去中心化身份+后量子加密+零知识证明构建三重防护
  • 模拟1000个智能体,2万次攻击全失败,验证率100%
  • 适合研究自主系统安全或构建可信AI生态的开发者

自主智能体的普及标志着复杂涌现式多智能体系统的范式转变,但也带来了控制流劫持和级联故障等系统性安全风险,传统网络安全方法难以应对。本文提出Aegis协议,一种分层安全框架,旨在为开放的智能体生态系统提供强安全保证。该协议融合三大技术支柱:(1) 借助W3C去中心化标识符(DIDs)实现不可伪造的智能体身份;(2) 采用NIST标准后量子密码(PQC)保障通信完整性;(3) 利用Halo2零知识证明(ZKP)系统实现可验证且隐私保护的策略合规性。我们扩展了Dolev-Yao模型以涵盖智能体威胁,并在STRIDE框架下验证协议。定量评估通过离散事件仿真进行,基于密码学基准校准,模拟1,000个智能体,结果显示在20,000次攻击试验中成功率均为0%。对于策略验证,仿真日志分析显示平均证明生成延迟为2.79秒,确立了此类安全机制的性能基线。尽管评估为仿真驱动且处于早期阶段,但仍为未来实证研究提供了可复现基准,奠定了Aegis作为安全、可扩展自主智能体基础的可行性。

原文摘要 · Abstract (English)

The proliferation of autonomous AI agents marks a paradigm shift toward complex, emergent multi-agent systems. This transition introduces systemic security risks, including control-flow hijacking and cascading failures, that traditional cybersecurity paradigms are ill-equipped to address. This paper introduces the Aegis Protocol, a layered security framework designed to provide strong security guarantees for open agentic ecosystems. The protocol integrates three technological pillars: (1) non-spoofable agent identity via W3C Decentralized Identifiers (DIDs); (2) communication integrity via NIST-standardized post-quantum cryptography (PQC); and (3) verifiable, privacy-preserving policy compliance using the Halo2 zero-knowledge proof (ZKP) system. We formalize an adversary model extending Dolev-Yao for agentic threats and validate the protocol against the STRIDE framework. Our quantitative evaluation used a discrete-event simulation, calibrated against cryptographic benchmarks, to model 1,000 agents. The simulation showed a 0 percent success rate across 20,000 attack trials. For policy verification, analysis of the simulation logs reported a median proof-generation latency of 2.79 seconds, establishing a performance baseline for this class of security. While the evaluation is simulation-based and early-stage, it offers a reproducible baseline for future empirical studies and positions Aegis as a foundation for safe, scalable autonomous AI.

智能体安全零知识证明后量子密码去中心化身份

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。