arXiv:2608.21049cs.CRcs.AI2026-08

提出可验证的6G网络智能控制架构,保障多厂商协作下的安全与审计。

$Z^2$-ACT: End-to-End Verifiable Agentic Intent Control for Open 6G RAN

论文配图:$Z^2$-ACT: End-to-End Verifiable Agentic Intent Control for Open 6G RAN
图 1 · 摘自论文原文
  • 用零知识证明和意图合约实现跨域可审计控制
  • 在近实时路径中实现攻击防御与低延迟信号开销
  • 适合关注6G安全与可信智能控制的研究者

随着开放化、解耦化的6G无线接入网发展,系统需支持多厂商共存。为保障多厂商环境下AI控制环路的安全性、可验证性与可审计性,现有研究分别处理智能体协调、形式化意图约束、零信任提示验证及密码学问责,但单独使用时仍存在安全预实现不完整、持续语义验证缺失与跨域审计不足的问题。为此,本文提出 $Z^2$-ACT 架构,集成上述四项核心机制于非实时与近实时RIC中。将类型化意图合约编码为操作员目标,仅在通过对抗性意图检查后才接受大语言模型输入。技能序列仅在满足自管理门限后释放,且每次成功提交均以零知识证明记录为不可否认承诺。基于公开ColO-RAN数据集的实验评估对比了完整架构与关键模块消融,并与传统强化学习基线比较。非实时路径使用真实大语言模型将操作员意图转化为意图合约,报告了转化准确率、无效或幻觉合约比例、非实时延迟,以及对抗或误导性意图下的行为表现;近实时控制基于公开KPM序列进行追踪驱动。结果表明,在近实时范围内实现了更好的动作过滤能力与抗攻击韧性,且延迟与信令开销适中。

原文摘要 · Abstract (English)

With the progression in open and disaggregated 6G radio access networks, it is expected that the system will be able to host multi-vendors. In order to host multi-vendors, it is essential that AI-assisted control loops remain safe, verifiable, and auditable under concurrent operator intents and untrusted model inputs. The existing studies address the agentic coordination, formal intent constraints, zero-trust prompt verification and cryptographic accountability in isolation, which leaves pre-realization safety, continuous semantic verification and cross-domain audit incomplete when used individually. In this regard, we propose zero-knowledge auditable control and zero-trust verifiable agentic intent architecture ($Z^2$-ACT), which integrates the aforementioned four primitives across the non-real-time and near-real-time RICs. We encode the typed Intent Contracts as operator goals while the large language model inputs are only admitted after a practical adversarial intent check. The skill sequences in the proposed study are released only when a self-management gate is satisfied while every successful commit is recorded as a binding commitment with a zero-knowledge proof. Our experimental evaluation on public ColO-RAN measurements compares the full architecture against targeted ablations and a conventional reinforcement-learning baseline. A live large language model is used in the non-real-time path to translate operator intents into Intent Contracts; we report translation accuracy, the rate of invalid or hallucinated contracts, non-real-time latency, and behavior under adversarial or misleading intents. Near-real-time control remains trace-driven on the public KPM sequences. Results indicate improved actuation filtering and attack resilience at modest latency and signaling cost inside the near-real-time envelope.

6G网络智能控制零知识证明可信计算

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。