发表机构
School of Computer Science, Dublin City University; Munster Technological University; National and Kapodistrian University of Athens(都柏林城市大学计算机科学学院; 芒斯特理工大学; 雅典国立与卡波迪斯特里亚大学)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
针对开放6G RAN多厂商部署的安全可验证需求,提出$Z^2$-ACT架构,集成多类核心组件并经实验验证其执行过滤与攻击恢复能力提升。
AI 中文摘要
随着开放、解耦的6G无线接入网(RAN)的发展,该系统有望支持多厂商部署。为实现多厂商支持,AI辅助控制环路必须在并发运营商意图和不可信模型输入下保持安全、可验证和可审计。现有研究分别处理智能体协调、形式化意图约束、零信任提示验证和密码学问责,单独使用时会导致预实现安全、连续语义验证和跨域审计存在缺陷。为此,我们提出零知识可审计控制与零信任可验证智能体意图架构($Z^2$-ACT),将上述四个核心组件集成到非实时和近实时RIC(无线智能控制器)中。我们将类型化意图合约编码为运营商目标,仅在经过实用的对抗性意图检查后才允许大型语言模型(LLM)输入。本研究中的技能序列仅在自管理门满足要求时才会发布,每次成功提交都会记录为带有零知识证明的绑定承诺。我们基于公开ColO-RAN测量值对完整架构、针对性消融模型和传统强化学习基线进行实验评估。非实时路径中使用实时LLM将运营商意图转换为意图合约;我们报告了翻译准确率、无效或幻觉合约的比例、非实时延迟以及在对抗性或误导性意图下的表现。近实时控制基于公开KPM序列的跟踪数据驱动。结果表明,在近实时范围内,该架构在适度延迟和信令成本下,执行过滤和攻击恢复能力得到提升。
英文摘要
With the progression in open and disaggregated 6G radio access networks, it is expected that the system will be able to host multi-vendors. In order to host multi-vendors, it is essential that AI-assisted control loops remain safe, verifiable, and auditable under concurrent operator intents and untrusted model inputs. The existing studies address the agentic coordination, formal intent constraints, zero-trust prompt verification and cryptographic accountability in isolation, which leaves pre-realization safety, continuous semantic verification and cross-domain audit incomplete when used individually. In this regard, we propose zero-knowledge auditable control and zero-trust verifiable agentic intent architecture ($Z^2$-ACT), which integrates the aforementioned four primitives across the non-real-time and near-real-time RICs. We encode the typed Intent Contracts as operator goals while the large language model inputs are only admitted after a practical adversarial intent check. The skill sequences in the proposed study are released only when a self-management gate is satisfied while every successful commit is recorded as a binding commitment with a zero-knowledge proof. Our experimental evaluation on public ColO-RAN measurements compares the full architecture against targeted ablations and a conventional reinforcement-learning baseline. A live large language model is used in the non-real-time path to translate operator intents into Intent Contracts; we report translation accuracy, the rate of invalid or hallucinated contracts, non-real-time latency, and behavior under adversarial or misleading intents. Near-real-time control remains trace-driven on the public KPM sequences. Results indicate improved actuation filtering and attack resilience at modest latency and signaling cost inside the near-real-time envelope.
Comments12 pages, 2 figures, 6 tables