发表机构
Phionyx Research(菲奥尼克斯研究院)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
AIREP是一种用于记录自动化AI运行时治理决策的协议,以签名对象形式存储决策,通过SHA-256哈希链防篡改,可供相关AI运行时采用。
AI 中文摘要
本文提出了一种用于记录自动化AI运行时治理决策的协议AIREP。当运行时发布、阻止、推迟、编辑或升级单个输出时,AIREP会将该决策记录为单个签名对象,任何方均可离线检查,且与生成该决策的运行时无关。记录会将决策表示为给定策略依据下的一组封闭动词之一,通过哈希而非值引用其输入、输出和证据,并声明其证据涵盖的内容及未涵盖的内容。记录形成SHA-256哈希链,将每条记录绑定到其位置,从而可通过重新计算检测篡改和缺口。供应商、模型和领域特定内容被限制在单个可选命名空间中,且机械中立测试确保共享格式不受其影响。本文描述了参考实现和双语言一致性套件,考虑了一些实现问题,揭示了跨实现的规范形式对齐、新鲜度见证者以及多运行时链等问题。该格式可供任何记录治理决策的AI运行时采用。
英文摘要
Runtime-governance evidence often collapses materially different events into one audit record: a decision may be made, an instruction dispatched or received, an action may or may not execute, and a resulting state may or may not be observed. This paper presents AIREP, a vendor- and model-independent protocol for per-decision AI runtime evidence. Its current wire model separates evidence into four artifact families: Decision, Control, Execution, and Effect. Artifacts use closed core schemas, explicit identities and digests, declared scope limits, RFC 8785 canonical JSON, domain-separated SHA-256 hashing, and pure Ed25519 signatures. A three-level assurance model distinguishes structural/hash consistency (AIREP-Core), verifier-accepted authorship (AIREP-Authenticated), and independently anchored chain-head freshness and non-truncation relative to an accepted witness (AIREP-Witnessed); these classes do not establish event truth. A structured reconciler preserves failure, missing evidence, unevaluated prerequisites, and indeterminate outcomes as distinct states. The released beta includes a four-family first-party producer, Python and Node reference-verification paths, adversarial/lifecycle corpora, and reproducible validation. Post-release first-party Hermes and LightEval integration exercises preserve explicit evidence boundaries without claiming adoption or interoperability. Independent implementation evidence exists separately for a v0.1.2 producer and a v0.2 consumer/verifier; because they target different frozen versions, they do not establish same-version producer-to-consumer interoperability. AIREP remains experimental.
Comments14 pages, 4 tables. Substantially revised v2: four-family Decision-Control-Execution-Effect model; deterministic wire/integrity construction; bounded assurance and lifecycle reconciliation; updated implementation and independent-implementation evidence; non-normative Hermes and LightEval integrations. Code/spec/evidence: https://github.com/halvrenofviryel/ai-runtime-evidence-protocol