发表机构
Information Engineering University(信息工程大学)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
AID-Guard是首个统一智能体授权生命周期控制的有状态协议,经多平台测试可阻止未授权效应,在保证安全性的同时可通过类型化前沿恢复部分效用。
AI 中文摘要
使用工具的AI智能体将委托任务转化为提供者效应,但授权通常在准入阶段就结束,而提供者状态、交付、重试和恢复过程仍在不断变化。请求可能在提交前发生变更,或响应丢失可能导致一次批准产生第二个效应。我们提出AID-Guard,一种面向效应闭环的有状态授权协议。该协议在提交时重新验证已批准的请求和提供者状态,在存在歧义时保留一个预留项,且仅在出现最终结果或通过交付围栏确认无效应后才允许释放或生成一个后继项。对于支持的提供者合约,一个预留项在重试和恢复过程中最多产生一个效应。据我们所知,这是首个经过评估的智能体授权协议,将这些控制措施统一到一个生命周期中。我们实现了一个Python/SQLite原型。在声明的回环MCP域中,13个实时变异未导致未授权的提供者效应,三个并发历史是线性化的,证据包支持公开验证和重放。所有210个Stripe提供者合约试验均与预先声明的结果匹配。在Stripe和Resend上,40个终端化后继调度、30个重叠竞态和10个崩溃恢复调度均无重复效应完成。在提议者完全被攻陷的情况下,AID-Guard阻止了44/44次攻击,且批准了44/44个匹配的合法提议。其严格的精确清单配置文件将良性效用降低了35.4至43.8个百分点;类型化前沿恢复了9-10次完成,且未观察到不安全效应。组合研究阻止了20/20次准入后生命周期攻击,并保留了8/8个有效或精确重试执行。结果支持在评估的效应路径清单、提供者合约和故障调度下实现授权到效应的绑定。
英文摘要
Tool-using AI agents turn delegated tasks into provider effects, yet authorization often ends at admission while provider state, delivery, retry, and recovery evolve. A request may change before commit, or response loss may cause a replacement to create a second effect from one approval. We present AID-Guard, a stateful authorization-to-effect closure protocol. It revalidates the approved request and provider state at commit, retains one reservation under ambiguity, and permits release or one successor only after a terminal result or certified no effect with a delivery fence. For supported provider contracts, one reservation yields at most one effect across retry and recovery. To our knowledge, it is the first evaluated agent-authorization protocol to unify these controls in one lifecycle. We implement a Python/SQLite prototype. In a declared loopback MCP domain, 13 live mutations caused no unauthorized provider effects, three concurrent histories were linearizable, and evidence bundles supported public verification and replay. All 210 Stripe provider-contract trials matched predeclared outcomes. Across Stripe and Resend, 40 terminalize-successor schedules, 30 overlapping races, and 10 crash-recovery schedules completed without duplicate effects. Under complete proposer compromise, AID-Guard blocked 44/44 attacks and admitted 44/44 matched legitimate proposals. Its strict exact-manifest profile reduced benign utility by 35.4 to 43.8 percentage points; a typed frontier recovered 9-10 completions without observed unsafe effects. A composition study blocked 20/20 post-admission lifecycle attacks and preserved 8/8 valid or exact-retry executions. The results support authorization-to-effect binding under the evaluated effect-path inventory, provider contracts, and failure schedules.
Comments18 pages, 8 figures, 13 tables. Preprint