arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

人工智能中最小自主性理论

A Theory of Least Autonomy in AI

Christophe Parisel

arXiv 2607.09744首次发表:更新:

AI 中文总结

研究智能代理人工智能系统权限控制问题,提出最小自主性理论,通过定义组合爆炸半径、有向代理影响图及勾结谓词,实现对系统中行动结构分离、代理影响及授权组合等的衡量与检测。

AI 中文摘要

最小权限原则,即身份应仅拥有其任务严格所需的权限,几十年来一直是访问控制的基础原语。我们认为该原则对智能代理人工智能系统不足,因其不仅持有权限,还能跨工作流和系统边界组合、批准和放大权限。我们提出最小自主性作为适当的概括并发展出形式理论。首先定义组合爆炸半径d(a,b)来衡量企业层级中行动间的结构分离;其次定义有向代理影响图G(theta);最后定义基于图可达性的勾结谓词来检测授权组合等。

英文摘要

Least privilege, the principle that an identity should hold only the permissions strictly required for its task, has been a foundational primitive of access control for decades. We argue that this principle is insufficient for agentic AI systems, which do not merely hold permissions but can combine, approve, and amplify them across workflows and system boundaries. We propose least autonomy as an appropriate generalization and develop a formal theory. First, we define a compositional blast radius d(a,b) that measures structural separation between actions in an enterprise hierarchy, combining an ultrametric tree with lattice-valued confidentiality, integrity, and control-context labels. Second, we define a directed agent influence graph G(theta). An arc from U to V requires a directed shared-resource write-to-read meeting or a conservative undirected agent-to-agent (A2A) communication meeting, and a meeting-conditioned influence potential at or above an externally selected policy threshold theta. A catalogue-radius profile supports calibration and audit of theta. Finally, we define a collusion predicate over graph reachability that detects authorization composition, decision manipulation, and cross-domain capability composition.

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑