稳定性赢得时间:加密多智能体控制的重新密钥生成博弈
Stability Buys Time: A Re-Keying Game for Encrypted Multi-Agent Control
浏览论文内容
中文总结 AI 辅助
研究加密多智能体控制中CKKS方案密钥恢复漏洞问题,将循环安全性建模为两阶段博弈,通过重新密钥生成防御主动操纵,确定了FHE精度等三方张力范围及有效安全点,揭示反馈回路中密码系统安全性是动态博弈。
中文摘要 AI 辅助
加密控制可让云在完全同态加密状态下协调一组智能体,同时保持其位置和命令的私密性。实值控制的近似方案CKKS返回的解密结果会携带加密噪声,这是一种密钥恢复漏洞;由于循环必须解密才能驱动,所以这种漏洞不可避免。然而,近似全同态加密(FHE)的安全性是静态研究的,加密控制假定云是诚实但好奇的,并且持续威胁博弈从未深入到密码系统内部。我们将高级持续威胁下循环的安全性建模为一个两阶段博弈,即被动侦察然后是主动操纵,由一个仅能看到操纵行为的测量残余检测器分隔开。被动阶段简化为已知的泛洪权衡;主动防御是重新密钥生成,而不是自举,因为只有重新密钥生成才能重置累积的泄漏。主动阶段是一个检测规避定时博弈:公开操纵会被发现,所以理性对手会保持隐秘,在其斯塔克尔伯格均衡中,防御者以最懒的节奏重新密钥生成,这由图拓扑的控制理论脆弱性决定。边缘稳定图必须比连接良好的图更频繁地重新密钥生成。FHE精度、控制精度和重新密钥生成节奏之间的三方张力决定了这个博弈的存在范围,介于安全底线和静态足够上限之间。有效的安全点是那个窗口,在那里重新密钥生成是精度效率的代价。更广泛地说,反馈回路中近似密码系统的安全性是一个动态博弈,其防御者的行动是该方案自身的刷新,这适用于任何必须反复解密才能行动的系统。
英文摘要
Encrypted control lets a cloud coordinate a fleet of agents on fully homomorphically encrypted state, keeping their positions and commands private. The approximate scheme for real-valued control, CKKS, returns decryptions that carry the encryption noise, a key-recovery leak; the loop must decrypt to actuate, so the leak is unavoidable. Yet the security of approximate FHE is studied statically, encrypted control assumes an honest-but-curious cloud, and persistent-threat games never reach inside the cryptosystem. We model the loop's security under an advanced persistent threat as a two-phase game, passive reconnaissance then active manipulation, separated by a measured residual detector that sees only the manipulation. The passive phase reduces to the known flooding tradeoff; the active defense is re-keying, not bootstrapping, since only re-keying resets accumulated leakage. The active phase is a detection-evasion timing game: overt manipulation is caught, so the rational adversary stays stealthy, and at its Stackelberg equilibrium the defender re-keys on the laziest cadence that denies it, set by the control-theoretic fragility of the graph topology. The marginally-stable graph must re-key far more often than the well-connected one. A three-way tension among FHE precision, control accuracy, and re-key cadence sets where this game lives, between a securability floor and a static-suffices ceiling. The efficient secure point is that window, where re-keying is the price of precision efficiency. More broadly, security for an approximate cryptosystem in a feedback loop is a dynamic game whose defender's move is the scheme's own refresh, applying beyond control to any system that must repeatedly decrypt to act.
发表机构
- University of Maryland, College Park(马里兰大学帕克分校)
机构由 AI 辅助整理,请以论文原文为准。