为自主智能体设计可验证的治理平台,符合美国国家标准局安全框架。
AAGATE: A NIST AI RMF-Aligned Governance Platform for Agentic AI
- 基于Kubernetes构建,整合威胁建模与风险评估框架
- 支持持续监控,能防范逻辑注入与认知退化等风险
- 适合需要合规部署的AI系统开发者和安全团队
本文提出Agentic AI Governance Assurance & Trust Engine(AAGATE),一个原生运行于Kubernetes的控制平面,旨在应对生产环境中由语言模型驱动的自主智能体带来的独特安全与治理挑战。针对传统应用安全工具对快速响应、机器级自主系统不适用的问题,AAGATE实现了美国国家标准与技术研究院(NIST)人工智能风险管理框架(AI RMF)的要求。其在各功能环节集成专用安全框架:使用MAESTRO进行‘识别’(Map),结合OWASP AIVSS与SEI SSVC进行‘度量’(Measure),并采用云安全联盟的智能体红队指南进行‘管理’(Manage)。通过零信任服务网格、可解释策略引擎、行为分析及去中心化责任追踪机制,AAGATE提供持续且可验证的治理能力,确保智能体的安全、可问责与可扩展部署。平台进一步扩展了数字身份权利框架(DIRF)、逻辑层注入防护(LPCI)以及认知退化监控(QSAF),全面覆盖系统性、对抗性与伦理风险。
原文摘要 · Abstract (English)
This paper introduces the Agentic AI Governance Assurance & Trust Engine (AAGATE), a Kubernetes-native control plane designed to address the unique security and governance challenges posed by autonomous, language-model-driven agents in production. Recognizing the limitations of traditional Application Security (AppSec) tooling for improvisational, machine-speed systems, AAGATE operationalizes the NIST AI Risk Management Framework (AI RMF). It integrates specialized security frameworks for each RMF function: the Agentic AI Threat Modeling MAESTRO framework for Map, a hybrid of OWASP's AIVSS and SEI's SSVC for Measure, and the Cloud Security Alliance's Agentic AI Red Teaming Guide for Manage. By incorporating a zero-trust service mesh, an explainable policy engine, behavioral analytics, and decentralized accountability hooks, AAGATE provides a continuous, verifiable governance solution for agentic AI, enabling safe, accountable, and scalable deployment. The framework is further extended with DIRF for digital identity rights, LPCI defenses for logic-layer injection, and QSAF monitors for cognitive degradation, ensuring governance spans systemic, adversarial, and ethical risks.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。