构建云端可信AI代理平台,防止数据泄露与越权操作。
Trusted AI Agents in the Cloud
- 基于可信虚拟机与可信GPU,实现多代理嵌套隔离
- 支持跨主体信任验证,确保外部调用可追溯
- 适合需要合规与安全的云上多智能体系统
由大语言模型驱动的AI代理正越来越多地作为云服务部署,自主访问敏感数据、调用外部工具并与其它代理交互。然而,这些代理运行在复杂的多方生态中,不受信组件可能导致数据泄露、篡改或异常行为。现有保密虚拟机仅提供单二进制保护,无法保证跨主体信任、加速器级隔离或代理行为监管。我们提出Omega系统,通过端到端隔离、跨参与方可验证信任建立以及对所有外部交互的问责溯源,实现可信AI代理。Omega基于保密虚拟机与保密GPU构建可信代理平台,在单一保密虚拟机内托管多个代理并采用嵌套隔离;通过差分证明实现跨主体信任建立,并提供策略定义与执行框架,规范数据访问、工具使用和代理间通信,保障数据安全与合规。系统基于AMD SEV-SNP与NVIDIA H100实现,完全保护代理状态在虚拟机-显卡间的安全,同时保持高性能,支持高密度、合规的多代理云规模部署。
原文摘要 · Abstract (English)
AI agents powered by large language models are increasingly deployed as cloud services that autonomously access sensitive data, invoke external tools, and interact with other agents. However, these agents run within a complex multi-party ecosystem, where untrusted components can lead to data leakage, tampering, or unintended behavior. Existing Confidential Virtual Machines (CVMs) provide only per binary protection and offer no guarantees for cross-principal trust, accelerator-level isolation, or supervised agent behavior. We present Omega, a system that enables trusted AI agents by enforcing end-to-end isolation, establishing verifiable trust across all contributing principals, and supervising every external interaction with accountable provenance. Omega builds on Confidential VMs and Confidential GPUs to create a Trusted Agent Platform that hosts many agents within a single CVM using nested isolation. It also provides efficient multi-agent orchestration with cross-principal trust establishment via differential attestation, and a policy specification and enforcement framework that governs data access, tool usage, and inter-agent communication for data protection and regulatory compliance. Implemented on AMD SEV-SNP and NVIDIA H100, Omega fully secures agent state across CVM-GPU, and achieves high performance while enabling high-density, policy-compliant multi-agent deployments at cloud scale.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。