arXiv:2605.15228cs.AIcs.LG2026-05被引 3

用可验证证明取代身份认证,让自主智能体的执行受控可审计。

Verifiable Agentic Infrastructure: Proof-Derived Authorization for Sovereign AI Systems

  • 通过结构化证明文档定义操作合法性,实现可验证授权
  • 构建共识机制与证据链,确保高风险操作必有可追溯的证明
  • 适合需合规监管的国家级智能系统,如金融、政务场景

现代云与企业系统依赖基于身份的授权,假设持有有效凭证者可安全执行命令。但自主智能体的出现打破了这一假设:它们可生成语法正确但语义不安全的动作,使长期权限成为重大运营风险。该风险在主权人工智能系统中尤为突出,因智能体可能交互于云基础设施、受监管数据、金融流程及国家级数字服务。受控变异基底通过介入代理行为来降低风险:代理提交意图,基础设施评估上下文与策略,再决定是否执行。然而,信任边界随之转移——如何使授权决策具备可验证性、分布式和可重放性?我们提出分布式信任框架(DTF),一种面向受控变异系统的验证框架,其从结构化、可验证的实体中计算执行权限。DTF引入‘理由证明’以编码动作适切性的依据,采用共识模型进行独立评估,生成基于批准证明的临时执行身份,并维护不可篡改的证据链以记录授权生命周期。在既定基底假设下,该架构强制执行紧凑的授权不变式:无证明对象则禁止高风险执行,无共识则无衍生权限,无证据则无有效变更。我们定义了该模型,并在OpenKedge基础上实例化,展示其向云原生环境的映射。通过将授权从持续身份转向证明驱动的权威,DTF为智能体执行提供了可治理、可审计且受限的基础设施基础,适用于主权人工智能部署。

原文摘要 · Abstract (English)

Modern cloud and enterprise systems rely on identity-centric authorization, assuming that callers possessing valid credentials are safe to execute commands. The emergence of autonomous AI agents invalidates this assumption: agents can generate syntactically valid but semantically unsafe actions, making standing privileges a significant operational risk. This risk becomes especially acute in sovereign AI systems, where autonomous agents may interact with cloud infrastructure, regulated data, financial workflows, and national-scale digital services. Governed mutation substrates reduce this risk by interposing on agent actions: agents submit intents, infrastructure evaluates context and policy, and execution is mediated. However, this shifts the trust boundary: how can the decision to authorize an intent be made verifiable, distributed, and replayable? We introduce a Distributed Trust Framework (DTF), a verification framework for governed mutation systems that computes execution authority from structured, verifiable artifacts. DTF introduces a Justification Proof to encode the admissibility basis of an action, a consensus model for independent evaluation, an ephemeral Execution Identity derived from the approved proof, and an append-only Evidence Chain that preserves the authorization lifecycle. Under stated substrate assumptions, this architecture enforces a compact authorization invariant: no high-stakes execution without a proof object, no derived authority without consensus, and no valid mutation detached from evidence. We define the model, instantiate it over an OpenKedge-based governed mutation substrate, and show how it maps onto cloud-native environments. By shifting authorization from standing identity to proof-derived authority, DTF provides an infrastructure foundation for making agentic execution governable, auditable, and bounded in sovereign AI deployments.

AI安全可验证授权主权系统智能体

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。