arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

确认点即系统:用于AI审计证据的持久策略决策收据

The Acknowledgment Point Is the System: Durable Policy-Decision Receipts for AI Audit Evidence

Neeraj Kumar Singh Beshane

arXiv 2608.17176首次发表:更新:

AI 中文总结

该研究重构RuntimeGuard-AI,实现绑定策略源、带Ed25519签名收据的AI审计机制,在不同配置下达成可测的持久性-延迟权衡,同时明确其局限性。

AI 中文摘要

AI审计记录仅在其持久性和信任边界明确时才有用。在任何持久写入前返回受保护决策可最小化延迟,但无法保证证据在立即崩溃后仍留存。我们围绕该约束重构RuntimeGuard-AI。生成的研究原型将每个确定性策略决策绑定到精确的策略源,在调用者选定的同步边界提交隐私优化的记录,并返回Ed25519签名的收据,声明该边界是否完成。重启后,引擎会验证带框记录、清单、分片放置、序列连续性和重放身份。单独的证明路径将已提交记录分组为链式、签名的Merkle epoch,审计员可通过外部获取的密钥验证这些epoch。在Apple M4 Pro上,4个工作线程、2048字节提示下,缓冲的签名证据可达27193请求/秒,中位数延迟141.9微秒。每条记录数据和完全同步将吞吐量降至约242请求/秒,中位数延迟升至16.0毫秒。密封10万条记录的签名epoch需97.0毫秒。结果是可测的持久性-延迟权衡,而非“免费”的异步审计路径。该原型未证明模型执行、无法防止被入侵的签名者分叉历史,也未确立法律合规性。

英文摘要

An AI audit record is useful only if its durability and trust boundary are explicit. Returning a guarded decision before any durable write minimizes latency, but it cannot guarantee that evidence survives an immediate crash. We rebuild RuntimeGuard-AI around this constraint. The resulting research prototype binds each deterministic policy decision to the exact policy source, commits a privacy-minimizing record at a caller-selected synchronization boundary, and returns an Ed25519-signed receipt that states whether that boundary completed. After restart, the engine validates framed records, manifests, shard placement, sequence continuity, and replay identity. A separate attestation path groups committed records into chained, signed Merkle epochs that an auditor verifies with an externally obtained key. On an Apple M4 Pro at four worker threads and 2,048-byte prompts, buffered signed evidence reaches 27,193 requests/s with 141.9 microseconds median latency. Per-record data and full synchronization reduce throughput to approximately 242 requests/s and raise median latency to 16.0 ms. Sealing a 100,000-record signed epoch takes 97.0 ms. The result is a measured durability-latency trade-off, not a "free" asynchronous audit path. The prototype does not prove model execution, prevent a compromised signer from forking history, or establish legal conformity.

Comments6 pages, 4 figures, 2 tables. Code and release artifacts: https://github.com/neerazz/RuntimeGuard-AI/releases/tag/v2.0.0

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑