发表机构
Max Planck Institute for Software Systems; Research Institute for Cryptoeconomics, Vienna University of Economics and Business(马克斯·普朗克软件系统研究所; 维也纳经济与商业大学密码经济学研究所)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
该研究提出Agent Flight Recorder,通过结构化事件绑定、哈希链与默克尔批处理及链上锚定,实现长周期工具使用智能体的防篡改审计轨迹,经评估其性能与验证能力优异。
AI 中文摘要
长周期智能体会执行数千个动作,由此产生的故障是序列性的,而非孤立错误。当编码智能体删除生产数据库,或提示注入在智能体间传播时,该事件会引发关于因果关系、权限以及不可否认的第三方验证的问题。Agent Flight Recorder(智能体飞行记录仪)将每个智能体动作捕获为结构化、规范序列化的事件,绑定从意图到执行再到来源的八个语义字段。哈希链和默克尔批处理提供防篡改证据和紧凑的包含证明。对于无任何一方基础设施可作为中立平台的跨组织纠纷,周期根的定期链上锚定可让任何拥有公开有效载荷和默克尔证明的验证者独立检查记录,无需预先约定可信中介。链上占用空间极小:每个锚定存储一个32字节的周期根和一个回指指针,无任何事件内容触及链。我们在合成智能体工作负载上,针对五种累积消融配置评估该系统。完整系统每个事件的中位数延迟增加约48微秒,每个事件占用512字节;在100事件周期下,L2锚定每10万事件成本为2.30美元。完整完整性栈以100%的准确率检测编辑、删除、重排序和分叉篡改,无假阳性;结构化取证查询在护栏和委托查找上的准确率达1.0,而非结构化文本搜索分别仅为0.013和0.077。
英文摘要
Long-horizon agents execute thousands of actions, resulting in sequential failures rather than isolated errors. When a coding agent deletes a production database or a prompt injection spreads across agents, the incident raises questions of causality, authority, and non-repudiable third-party verification. The Agent Flight Recorder captures each agent action as a structured, canonically serialized event binding eight semantic fields from intent through execution to provenance. Hash chaining and Merkle batching provide tamper evidence and compact inclusion proofs. For cross-organizational disputes where no party's infrastructure qualifies as neutral ground, periodic on-chain anchoring of epoch roots lets any verifier with the disclosed payload and Merkle proof check the record independently, without pre-agreeing on a trusted intermediary. The on-chain footprint is minimal: each anchor stores a 32-byte epoch root and a back-pointer, and no event content touches the chain. We evaluate the system across five cumulative ablation configurations on synthetic agent workloads. The full system adds ~48 microseconds median per-event latency and 512 bytes per event. L2 anchoring costs $2.30 per 100K events at 100-event epochs. The full integrity stack detects edit, delete, reorder, and fork tampering at 100% with zero false positives. Structured forensic queries achieve 1.0 precision on guardrail and delegation lookups where unstructured text search yields 0.013 and 0.077 respectively.
Comments9 pages, 1 figure, 4 tables. Accepted at BCCA 2026 (IEEE International Conference on Blockchain Computing and Applications)