arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

智能体原生遥测:面向自主操作的可验证状态增量证据

Agent-Native Telemetry: Verifiable State-Delta Evidence for Autonomous Operations

Jun He, Deying Yu

arXiv 2608.16178首次发表:更新:

AI 中文总结

该研究提出智能体原生遥测架构,基于ATP协议和状态增量证据账本,在微服务基准测试中大幅降低了数据开销、LLM资源消耗,且能检测对抗性突变、抵御提示注入攻击。

AI 中文摘要

操作遥测主要是为人类阅读而设计的:系统在数十亿条日志行中反复序列化冗长的文本、静态键和冗余上下文。随着自主AI智能体成为主要操作消费者,为其提供传统日志会浪费稀缺的上下文容量,用于解析词汇语法而非推理系统状态变化,同时缺乏关于来源或收集完整性的密码学保证。本文介绍智能体原生遥测,这是一种面向自主机器操作员的操作证据架构,基于可验证状态增量而非人类文本。我们提出智能体遥测协议(ATP)和状态增量证据账本,该实现将操作事实构建为四个核心证据原语(转换、观测、关系和状态检查点),由内容寻址模式管理,同时将未整理文本隔离为摘要验证的不透明引用。生产者对批次进行签名和哈希链处理,以便原子收集器追加。已验证记录提供两条并行智能体访问路径:无状态协议解码器生成紧凑位置行,以及有状态语义网关提供有界图胶囊。我们证明了信息保留下界,并形式化了相对于账本的已验证否定定理,用于可证明的事件未发生。在分布式微服务基准(AIOpsLab和OpenTelemetry Astronomy Shop)上,ATP相对于OpenTelemetry JSON将原始线路有效载荷和建模云查询扫描成本降低了96.4%,将LLM上下文令牌减少了88.8%,查询操作减少了66.2%,检测了所有500个测试的对抗性存储突变,且在每个ATP配置的50次对抗性试验中未出现成功的提示注入。

英文摘要

Operational telemetry is predominantly engineered for human reading: systems repeatedly serialize verbose prose, static keys, and redundant context across billions of log lines. As autonomous AI agents become primary operational consumers, feeding them traditional logs wastes scarce context capacity parsing lexical syntax rather than reasoning over system state changes -- all while lacking cryptographic guarantees of provenance or collection completeness. This paper introduces agent-native telemetry, an operational evidence architecture for autonomous machine operators founded on verifiable state deltas rather than human prose. We present the Agent Telemetry Protocol (ATP) and the State-Delta Evidence Ledger, an implementation that structures operational facts into four core evidence primitives (Transitions, Observations, Relations, and State Checkpoints) governed by content-addressed schemas, while isolating uncurated text as digest-verified opaque references. Producers sign and hash-chain batches for atomic collector append. Verified records feed two parallel agent access paths: a stateless protocol decoder emitting compact positional rows, and a stateful semantic gateway serving bounded graph capsules. We prove an information-preservation lower bound and formalize a ledger-relative verified negative theorem for provable event non-occurrence. On distributed microservice benchmarks (AIOpsLab and OpenTelemetry Astronomy Shop), ATP reduces raw wire payload and modeled cloud query scan costs by 96.4% relative to OpenTelemetry JSON, reduces LLM context tokens by 88.8% and query operations by 66.2%, detects all 500 tested adversarial storage mutations, and yields zero successful prompt injections across 50 adversarial trials per ATP configuration.

Comments13 pages, 3 figures, 6 tables

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑