arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

AI智能体间的零知识谓词证明:一种可测量的跨协议网关与源完整性缺口

Zero-Knowledge Predicate Proofs Between AI Agents: A Measured, Cross-Protocol Gateway and the Source-Integrity Gap

Ashok Subbabhatta Gopalakrishna

arXiv 2608.30083首次发表:更新:

AI 中文总结

该研究提出一种跨协议零知识证明网关,实现AI智能体间的可证数据最小化,解决源完整性缺口问题,经实验验证性能达标且符合GDPR数据最小化原则。

AI 中文摘要

多智能体AI平台正快速从测试阶段过渡到生产环境,但智能体建立信任的方式仍很原始:要么向对等节点传输原始数据,要么接受对等节点关于某值符合策略的自然语言自我报告。前者过度共享数据,后者无法验证,且恰好是提示注入攻击的通道。主流应对方案强调身份、可见性和事后检测,近期基于密码学的智能体策略提案仅在模拟环境中评估,而非实际执行。我们将智能体间的可证数据最小化从提案推进到运行系统。在我们的零知识证明网关中,智能体交换针对私有数据的治理定义谓词的证明,而非数据本身,因此从设计上防止信息暴露,而非事后检测;由于没有互操作协议可承载此类证明,我们提出一种插槽,并在一个端点同时实现于MCP和Agent2Agent协议上。在一个商用vCPU上,32位阈值谓词的证明生成耗时6.2毫秒,验证耗时1.0毫秒,对应的Bulletproofs证明大小为608字节;11项对抗实验和19项协议检查均通过;系统已部署到Kubernetes,并经实验验证具备网络隔离性。我们的案例研究证明,零售客户订单在不泄露金额的情况下符合限额,将GDPR数据最小化原则实例化为欧盟法律明确要求的强制技术措施。随后,我们解决了一项同类工作未解决的局限:谓词证明将声明绑定到承诺值,而非记录系统。我们提出一种构造,将机密环境(enclave)认证与证明双向融合,因此验证单一工件可共同证明谓词成立且值由特定可测量二进制读取,并针对模拟权威机构进行了测试。

英文摘要

Multi-agent AI platforms move quickly from staging to production, but the way agents establish trust remains rudimentary: an agent either transmits raw data to a peer or accepts that peer's natural-language self-report that a value complies with policy. The first over-shares; the second is unverifiable and is exactly the channel prompt injection attacks. Prevailing responses emphasise identity, visibility, and post-hoc detection, and recent proposals for cryptographically enforced agent policy have been evaluated in simulation rather than execution. We take provable data minimisation between agents from proposal to running system. In our Zero-Knowledge Proof Gateway, agents exchange proofs of governance-defined predicates over private data rather than the data itself, so exposure is prevented by design rather than detected afterwards; because no interoperability protocol can carry such a proof, we propose a slot and implement it on both MCP and Agent2Agent from one endpoint. A 32-bit threshold predicate proves in 6.2 ms and verifies in 1.0 ms with a 608-byte Bulletproofs proof on one commodity vCPU; eleven adversarial experiments and nineteen protocol checks pass; and the system is deployed to Kubernetes with empirically verified network isolation. Our case study proves a retail client order is within its limit without revealing the amount, instantiating the GDPR data-minimisation principle as an enforced technical measure of the kind EU law now names explicitly. We then address the limitation no comparable work resolves: a predicate proof binds a statement to a committed value, never to the system of record. We give a construction fusing an enclave attestation with the proof in both directions, so verifying one artifact certifies jointly that the predicate holds and that the value was read by a specific measured binary, and test it against a mock authority.

Comments11 pages, 6 figures, 4 tables. Reference implementation available at https://github.com/45h0kg/zk-proof-gateway

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑