提出最小自主性理论,应对智能体系统权限滥用风险
A Theory of Least Autonomy in AI
- 用层次化树结构与多值标签量化动作间影响范围
- 通过有向影响图检测跨系统权限组合与决策操纵
- 适用于需审计和控制智能体协同的高安全场景
最小特权原则在访问控制中已应用数十年,但对具有自主行为能力的智能体系统而言已显不足。本文提出‘最小自主性’作为其合理延伸,并构建形式化理论:首先定义可组合的爆炸半径 d(a,b),融合超度量树与保密性、完整性及控制上下文的格值标签,衡量企业层级中动作间的结构隔离程度;其次定义有向代理影响图 G(theta),当存在定向资源写读交汇或保守的代理间通信交汇,且影响潜力超过外部设定策略阈值 theta 时,即形成从 U 到 V 的有向边;最后定义基于图可达性的共谋谓词,可检测授权组合、决策操控及跨域能力合成,支持 theta 的校准与审计。
原文摘要 · Abstract (English)
Least privilege, the principle that an identity should hold only the permissions strictly required for its task, has been a foundational primitive of access control for decades. We argue that this principle is insufficient for agentic AI systems, which do not merely hold permissions but can combine, approve, and amplify them across workflows and system boundaries. We propose least autonomy as an appropriate generalization and develop a formal theory. First, we define a compositional blast radius d(a,b) that measures structural separation between actions in an enterprise hierarchy, combining an ultrametric tree with lattice-valued confidentiality, integrity, and control-context labels. Second, we define a directed agent influence graph G(theta). An arc from U to V requires a directed shared-resource write-to-read meeting or a conservative undirected agent-to-agent (A2A) communication meeting, and a meeting-conditioned influence potential at or above an externally selected policy threshold theta. A catalogue-radius profile supports calibration and audit of theta. Finally, we define a collusion predicate over graph reachability that detects authorization composition, decision manipulation, and cross-domain capability composition.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。