arXiv:2606.04104cs.SEcs.AI2026-06被引 2

为异构智能体系统设计可移植的运行时治理框架,用数字证书统一管控高风险操作。

Proof-Carrying Agent Actions: Model-Agnostic Runtime Governance for Heterogeneous Agent Systems

  • 以动作证书为核心,跨平台统一管理权限与审批流程。
  • 在96条跨四类运行时的测试中保持路线质量,暴露不同失效模式。
  • 支持外部性感知和可执行性分类审批,适合多系统集成场景。

智能体系统在不同运行时环境中存在显著差异:本地编码工具、框架SDK、托管平台、API网关及仅观察式集成。高风险操作如对外发布数据,在不同环境中可能表现为命令行指令、工具调用或会话切换。这导致难以一致回答治理问题:谁授权了何种动作、依据何种审批逻辑、执行后有何证据?本文提出证明携带型智能体动作(PCAA),一种以动作证书为中心的运行时无关治理模型。该模型围绕五个检查点组织控制:事前合规性、动作开启、假设捕获、审批与结果闭环。通过可移植的动作封装、运行时与审批凭证,以及可重放的证明实现。模型扩展包括:证书具备外部性感知能力(如目标可见性、账户溯源),审批采用显式的可执行性类别而非单一审核状态。通过在异构代理控制平面中的参考实现及受限披露评估协议验证。在从24个可执行种子扩展至96条跨四类运行时的受保护基准上,PCAA保持路线质量的同时揭示了不同消融条件下的失效模式。论文贡献在于提出以带证动作为核心的系统化运行时治理范式,并展示了其在运行时演化下仍能保持可移植性的实现路径。

原文摘要 · Abstract (English)

Agent systems execute through runtimes with very different control points: local coding tools, framework SDKs, managed agent platforms, API gateways, and observer-only integrations. A high-risk action such as publishing data externally may therefore appear as a shell command in one runtime, a tool call in another, and a hosted session transition in a third. This makes it difficult to answer a basic governance question consistently: what action was authorized, under whose authority, with what approval semantics, and with what evidence after execution? This paper presents Proof-Carrying Agent Actions (PCAA), a runtime-neutral governance model centered on an action certificate rather than on a vendor-native session record. PCAA organizes control around five checkpoints: pre-action admissibility, action open, assumption capture, approval, and outcome closure. It binds these checkpoints to a portable action envelope, runtime and approval receipts, and replay-ready proof. The model is extended in two practical ways: the certificate is externality-aware, carrying boundary facts such as destination visibility and account provenance, and approval is described by explicit enforceability classes rather than by a single reviewed or unreviewed bit. We study the model through a reference implementation in a heterogeneous agent control plane and a disclosure-bounded evaluation protocol. On a protected benchmark expanded from 24 executable seeds to 96 traces across four runtime families, PCAA preserves route quality while exposing distinct failure modes under ablation. The paper contributes a systems formulation of runtime governance around certificate-bearing actions and an implementation-grounded account of how that formulation can remain portable under runtime churn without collapsing into vendor-specific control surfaces.

智能体系统运行时治理数字证书可移植性

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。