为多智能体联盟设计安全身份与治理机制,提升抗干扰能力与决策可靠性。
PRIMUS: Identity, Governance, and Verification for Multi-Agent Federations
- 用素数幂身份+聚合签名实现可验证参与,抗10%信道噪声
- 安全终止阈值将误杀率从80%降至0%,经济边界稳定在γ*=9f
- 可作优化引导的评分器,适合高可靠性系统与对抗性环境
多智能体联盟需在对抗环境下解决三重问题:谁参与(身份)、是否合规(执行)、由谁决策(权威)。同时需判断验证机制能否引导生成-测试循环获得更优结果。本文提出PRIMUS,将素数幂身份与BLS聚合签名结合(PIAC),在10%信道噪声下将错误终止率从80%降至0.00%,推导出单一治理优于拜占庭多数的经济边界(γ* ≈ 9f,n=50至10,000间恒定),并设计带租约与围栏的VRF继承机制,在部分同步下确保安全。五个问题被证明在模型内不可修复,列为边界。第二部分表明,验证器非求解器:将二元真伪判别转化为分级适应度信号,在二元覆盖码上校准显著(ρ=0.676确定性,0.819完整);但在真实LLM生成样本中仅得0.158和0.406,约为校准值的四分之一(同一设计者偏差)。作为预筛选,其表现优于随机控制,略胜于二元门控。400次显式优化后未被攻破,因目标在首次诚实答案后饱和。跨家族裁判保留负担排序信号,但破坏个体判断,未产生新覆盖码记录。程序成本:164.78美元。
原文摘要 · Abstract (English)
Multi-agent federations need governance that answers three questions under adversarial conditions: who participated (identity), did they conform (enforcement), and who decides (authority). A separate question is whether the verification machinery that polices a federation's outputs can also steer a generate-and-test loop toward better answers. Part I. PRIMA introduced prime-power agent identity and a consensus token whose factorization indexes participation, but assumed honest agents. We present PRIMUS, which couples prime-power identity with BLS aggregate signatures (PIAC), derives a safe-kill threshold that reduces false-positive agent termination from 80% to 0.00% under 10% channel noise, gives the closed-form economic boundary where singleton governance outperforms Byzantine quorum ($\gamma^* \approx 9f$, verified flat across n = 50 to 10,000), and specifies VRF succession with lease and fencing that makes safety unconditional under partial synchrony. Five problems are identified as provably unfixable within the model and stated as scope boundaries. Part II. A verifier is not a solver. We ask whether PRIMA's binary artifact-fidelity verdict can be converted into a graded fitness signal, and measure the conversion on binary covering codes. Calibration against injected fault burden is strong ($\rho$ = 0.676 deterministic, 0.819 full); against real LLM-generated candidates the same scores fall to 0.158 and 0.406, roughly a quarter of the calibration value (the same-designer confound, measured). As a pre-filter it beats a random-score control convincingly and a binary gate narrowly. Under 400 iterations of explicit optimization it was not gamed, but only because the objective saturated after one honest answer. A cross-family judge preserves the burden-ordering signal while destroying individual judgments. No covering-code record resulted. Measured program cost: USD 164.78.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。