arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2608.30387cs.CR

多智能体AI系统中的输出证明与委托谱系

Attesting Outputs and Delegation Ancestry in Multi-Agent AI Systems

Lifei Liu, Haoran Yu

首次发表
浏览论文内容

中文总结 AI 辅助

该研究针对多智能体AI系统的输出与委托谱系验证问题,提出两层证明设计,对比三种方案,经测试其验证效率满足多服务部署需求,可解决跨部署者的授权与溯源难题。

中文摘要 AI 辅助

多智能体应用会在独立运行的部署者之间委托工作。事件发生后,验证者必须回答两个问题:哪个部署者发布了报告的字节,以及每个跨部署者的边是否被授权。凭证确立了谁可以执行操作,但无需将其与后续输出字节绑定,也无需证明两个部署者都授权了动态创建的边。我们提出了一种两层证明设计,用于在无共享权威机构、公共日志或预提交工作流的情况下进行动态委托。可信部署者运行时对每个发布输出的哈希进行签名,这记录了发布的字节,但无法防止提示注入。谱系证据记录边授权。在统一威胁模型下,我们比较了签名链表、Merkle链变体和共同签名的DAG。这些原语是标准的,贡献在于部署者侧的绑定以及回答上述两个问题所需的证据。在子密钥泄露后,单签名设计允许未经授权的父绑定,而共同签名的DAG会拒绝这种情况,因为父必须授权边。固定敌手矩阵和回归测试验证了组合验证器。在Apple M1 Pro上,仅谱系检查每跳耗时24.3-499.2微秒。在实时本地多服务工作流中,父发现子的A2A Agent Card,子调用MCP工具并发布本地LLM输出:所有30个签名DAG任务通过完整验证,而受控的仅子密钥的声明被拒绝;其平均端到端延迟为813.1毫秒,无证据时为770.8毫秒。在互补的三可用区AWS部署中,所有1000条有效的共同签名DAG路径均通过验证;发布平均耗时3.651毫秒,完整验证平均耗时5.015毫秒。云结果未包含TLS/mTLS、KMS和模型服务延迟。

英文摘要

Multi-agent applications delegate work across independently operated deployers. After an incident, a verifier must answer two questions: which deployer released the reported bytes, and whether each cross-deployer edge was authorized. Credentials establish who may act, but need not bind them to later output bytes or prove both deployers authorized a dynamically created edge. We present a two-layer attestation design for dynamic delegation without a shared authority, public log, or precommitted workflow. A trusted deployer runtime signs a hash of each released output; this records released bytes but does not prevent prompt injection. Ancestry evidence records edge authorization. Under a unified threat model, we compare a signed linked list, a Merkle-chain variant, and a co-signed DAG. The primitives are standard; the contribution is deployer-side binding and the evidence needed for the two questions. After child-key compromise, the single-signer designs permit an unauthorized parent binding, whereas the co-signed DAG rejects it because the parent must authorize the edge. Fixed adversary matrices and regression tests validate the composed verifier. On an Apple M1 Pro, ancestry-only checks take 24.3-499.2us per hop. In a live local multi-service workflow, a parent discovers the child's A2A Agent Card; the child calls an MCP tool and releases local-LLM output: all 30 signed-DAG tasks passed complete verification, while a controlled child-key-only claim was rejected; its mean end-to-end latency was 813.1ms versus 770.8ms without evidence. In a complementary three-availability-zone AWS deployment, all 1,000 valid co-signed-DAG paths verified; issuance averaged 3.651ms and complete verification 5.015ms. The cloud result excludes TLS/mTLS, KMS, and model-serving latency.

↑