arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

将授权与披露分离:面向智能体动作调解的字段层级最小化

Separating Disclosure from Authorization: Field-Tier Minimization for Agent Action Mediation

Jiten Oswal, John Cadeddu

arXiv 2608.25474首次发表:更新:

AI 中文总结

该研究提出智能体动作调解的字段层级最小化方法,将参数字段分为三类,实现授权与披露分离,解决事实计算方问题并分析泄露,保障账本安全与审计需求。

AI 中文摘要

授权动作的系统必须查看足够的动作信息以做出决策,而证明其决策的系统必须记录足够的信息以供审计。这两种压力都将原始动作参数——接收方、支付备注、记录标识符——推送到无法删除的仅追加账本中。我们证明这两者是可分离的。我们将每个参数字段而非每个动作类分为三个层级:策略可合法匹配的字段,以原始形式传递;与策略相关但具标识性的字段,以投影形式传递,如电子邮件域名或模板化路由形状;无合法策略用途的字段,绝不离开工作负载。核心特性是账本承诺是完整未最小化参数的规范摘要,在最小化运行前计算,因此独立于层级表:重新分类字段会改变披露内容,而不会使历史条目无效、重新打开哈希或改变离线验证者的检查内容。层级表、策略模式和线路模式由每个动作声明生成,因此决策方和记录方不能持有不同规则。我们随后解决该架构提出的问题:哪一方应计算每个已证明事实?我们认为这由哪一方能在不被检测的情况下撒谎决定,并在单个请求中得出三个答案:客户端计算参数摘要,因其是唯一持有数据的一方;客户端被结构阻止命名管控它的定义,因为这会在签名账本中写入虚假陈述;客户端证明其应用的层级表,因此分歧可被检测。我们对每个投影进行泄露分析,报告一起首次投影保留了本应移除的标识符的事件,并说明该设计未消除的剩余信任。

英文摘要

A system that authorizes an action must see enough of it to decide, and a system that attests to its decision must record enough to be audited. Both pressures push raw action parameters -- recipients, payment memos, record identifiers -- into an append-only ledger that cannot delete them. We show the two are separable. We classify each parameter field, not each action class, into three tiers: fields a policy may legitimately match on, which cross raw; fields that are policy-relevant but identifying, which cross only as projections such as an email domain or a templated route shape; and fields with no legitimate policy use, which never leave the workload. The central property is that the ledger's commitment is a canonical digest of the full, unminimized parameters, computed before minimization runs. The commitment is therefore independent of the tier table: reclassifying a field changes what is disclosed without invalidating a historical entry, reopening a hash, or altering what an offline verifier checks. Tier table, policy schema and wire schema are generated from one per-action declaration, so the deciding and recording parties cannot hold different rules. We then address a question the architecture forces: which party should compute each attested fact? We argue it is settled by which party could lie about it undetectably, and derive three answers within one request -- the client computes the parameter digest, being the only party holding the data; it is structurally prevented from naming the definition that governed it, since that would write a false statement into a signed ledger; and it attests which tier table it applied, so divergence is detectable. We give a leakage analysis of each projection, report an incident in which a first-cut projection preserved the identifier it was written to remove, and state the residual trust the design does not eliminate.

Comments19 pages, 2 figures, 5 tables. Describes an implemented system in private pilot deployment

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑