为异构运行时的智能体行为建立统一可验证的行动标准,解决治理证据难追溯问题。
CAVA: Canonical Action Verification and Attestation for Runtime Governance of Agentic AI Systems
- 将多种运行时行为映射为统一的规范动作对象,实现跨平台一致表示。
- 在96个种子、384种变体测试中验证了动作身份一致性与审批绑定可靠性。
- 适合关注智能体治理、安全审计及合规性验证的研究者和开发者。
智能体系统日益通过异构运行时执行任务:本地代码钩子、SDK工具、浏览器自动化、托管代理日志、API网关和工作流引擎。单个操作如发布代码、更改身份状态、转账或导出数据,可能产生多个不兼容的运行时记录,导致基本治理问题难以回答:实际批准的是什么操作?批准如何与执行绑定?独立验证者能否复现相同动作身份?本文提出规范动作验证与认证(CAVA),作为将异构代理活动转换为规范运行时动作对象的运行时语义层。CAVA位于可携带证明的智能体动作(PCAA)之下:PCAA定义部署方拥有的路线审查-证明治理流程,而CAVA定义该流程所治理的稳定动作对象。本文形式化了规范动作身份、语义模式检测、审批绑定、接收完整性、运行时可移植投影及可选认证底座。通过一个包含96个种子、384种变体的基准测试,研究了语义等价性、语义分离性、封装绕过、误报控制、审批绑定、接收可复现性、认证篡改检测、运行时可移植性、语义模式检测、策略退化及Azure部署演练。贡献在于提出了以动作级归一化和可策略定位的语义模式为基础的系统框架,是部署方侧智能体治理的必要基础。
原文摘要 · Abstract (English)
Agentic AI systems increasingly act through heterogeneous runtimes: local coding hooks, SDK tools, browser automation, managed-agent traces, API gateways, and workflow engines. A single operational act such as publishing code, changing identity state, moving money, or exporting data may therefore be represented by many incompatible runtime records. This makes a basic governance question difficult to answer: what action was actually approved, what evidence binds the approval to execution, and can an independent verifier reproduce the same action identity later? This paper presents Canonical Action Verification and Attestation (CAVA), a runtime-semantics layer for converting heterogeneous agent activity into canonical runtime action objects. CAVA is positioned below Proof-Carrying Agent Actions (PCAA): PCAA defines the deployer-owned route-review-prove governance process, while CAVA defines the stable action object that process governs. The paper formalizes canonical action identity, semantic pattern detection, approval binding, receipt integrity, runtime-portable projection, and optional attestation substrates. We study a reference implementation through a 96-seed, 384-variant benchmark covering semantic equivalence, semantic separation, wrapper bypass, false-positive control, approval binding, receipt reproducibility, attestation tamper detection, runtime portability, semantic pattern detection, policy degradation, and Azure deployment drills. The contribution is a systems formulation of action-level canonicalization and policy-addressable semantic patterns as a necessary substrate for deployer-side AI governance.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。