发表机构
School of Electronic Information and Communications, the Huazhong University of Science and Technology; Peng Cheng Laboratory; Pazhou Laboratory (Huangpu); School of Mechanical Engineering and Electronic Information, China University of Geosciences (Wuhan); School of Artificial Intelligence, Xidian University(华中科技大学电子信息与通信学院; 鹏城实验室; 琶洲实验室(黄埔); 中国地质大学(武汉)机械工程与电子信息学院; 西安电子科技大学人工智能学院)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
针对智能体AI网络的声明与能力不一致及安全漏洞问题,提出双层区块链零信任框架TrustAgentNet,通过技能集链与协作链保障安全,实验验证其开销低、准确率高且能自主恢复。
AI 中文摘要
智能体AI网络(AgentNet)系统严重依赖第三方技能集实现与分布式多智能体协作,但在“按声明信任”的假设下面临“声明与能力不一致”及安全漏洞等重大问题。为解决该问题,本文提出TrustAgentNet,一种双层区块链安全的零信任框架。具体而言,全局技能集链(CoS)管控技能集元数据的生命周期,其协议由专用智能体赋能,可在维持轻量级链上密码共识的同时执行链下审计;此外,面向任务的临时协作链(CoC)被动态建立,以实现无信任的分布式多智能体协作。本文对安全级别、任务性能与资源开销三者间的权衡关系进行了理论分析并通过实验验证。硬件原型实验结果表明,与无区块链的“按默认信任”基线相比,TrustAgentNet的零信任开销主要由链下推理主导,而区块链层通过账本-IPFS存储及链上/链下集成设计产生的账本成本极小。关键的是,所提验证流程在50个AI模型上实现了100%的完美准确率,正确验证了40个诚实技能集并拦截了10个对抗性技能集;在非AI领域,其在171个ClawHub技能的1478个特征上达到83.91%的准确率与0.85的F1分数,且对抗性实验进一步表明,TrustAgentNet可实现针对各类恶意攻击的自主技能集自我恢复。
英文摘要
Agentic AI networking (AgentNet) systems rely heavily on third-party skillset implementations and distributed multi-agent collaboration, yet they face major claim-to-capability inconsistencies and security vulnerabilities under trust-by-declaration assumptions. To bridge this gap, this paper proposes TrustAgentNet, a dual-tier blockchain-secured zero-trust framework. Specifically, a global Chain of Skillsets (CoS) governs the lifecycle of skillset metadata with protocols empowered by specialized agents to enforce off-chain auditing while maintaining lightweight on-chain cryptographic consensus. Furthermore, transient, task-oriented Chains of Collaboration (CoC) are dynamically established to enable trustless distributed multi-agent collaboration. Theoretical analysis of the three-way trade-off among security level, task performance, and resource overhead is provided and empirically validated. Experimental results on a hardware prototype demonstrate that compared with no-blockchain trust-by-default baselines, the zero-trust overhead of TrustAgentNet is dominated by off-chain inference, while the blockchain layer incurs minor ledger costs via the ledger-IPFS storage and on/off-chain integration design. Crucially, the proposed verification pipeline achieves a flawless 100% accuracy across 50 AI models, correctly validating 40 honest skillsets and intercepting 10 adversarial ones, and generalizes to non-AI domains with an 83.91% accuracy and a 0.85 F1-score across 1478 features from 171 ClawHub skills. Adversarial experiments further show that TrustAgentNet enables autonomous skillset self-recovery against various malicious attacks.
CommentsAccepted at IEEE Transactions on Cognitive Communications and Networking