arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2609.05269cs.CRcs.AI

CONTINUITY:用于可组合LLM智能体控制的安全-上下文契约

CONTINUITY: Security-Context Contracts for Composable LLM Agent Controls

Chris Zheng, Geng Yang

首次发表
浏览论文内容

中文总结 AI 辅助

针对LLM智能体跨组件的安全-上下文不连续性问题,提出CONTINUITY框架,通过可验证组合的安全控制契约,在2560次攻击测试中实现无有害效果,保障智能体执行安全。

中文摘要 AI 辅助

LLM智能体系统日益将溯源跟踪、授权、策略执行、协议适配器和执行控制相结合,但单独正确的安全机制未必能组合成端到端安全系统:当动作跨组件边界时,安全关键上下文可能被丢弃、拓宽、反弹或重新解释,我们将此失败模式称为安全-上下文不连续性,并引入CONTINUITY,一个用于智能体安全控制可验证组合的框架。CONTINUITY采用假设-保证契约对每个组件建模,通过签名根授权、溯源承诺、角色绑定的过渡收据、有界类型释放、转换见证和效果绑定的执行许可,在过渡过程中传递已认证的安全上下文。我们形式化端到端后果完整性,要求每个已实现的外部效果必须由有效且当前的授权见证支持,该见证关联主体、任务、溯源、委托、策略状态、规范动作和终局边界。我们实现了一个参考验证器和确定性跨层故障注入套件,覆盖四个应用领域的32类故障。在跨越128类故障域的2560个参数化攻击实例中,完整的CONTINUITY配置未造成任何有害外部效果,同时完成全部700个良性任务,并升级全部200个模糊案例。这些结果表明,安全的智能体执行不仅需要健全的单独控制,还需要显式契约,以在从指令到效果的完整路径中保留其保障。

英文摘要

LLM agent systems increasingly combine provenance tracking, authorization, policy enforcement, protocol adapters, and execution controls. However, individually correct security mechanisms do not necessarily compose into an end-to-end secure system: security-critical context may be dropped, widened, rebound, or reinterpreted as actions cross component boundaries. We identify this failure mode as security-context discontinuity and introduce CONTINUITY, a framework for verifiable composition of agent security controls. CONTINUITY models each component with an assume-guarantee contract and carries authenticated security context across transitions using signed root grants, provenance commitments, role-bound transition receipts, bounded typed releases, transformation witnesses, and effect-bound execution permits. We formalize end-to-end consequence integrity, requiring every realized external effect to be backed by a valid and current authorization witness linking the principal, task, provenance, delegation, policy state, canonical action, and finality boundary. We implement a reference verifier and deterministic cross-layer fault-injection suite covering 32 fault classes across four application domains. In 2,560 parameterized attack instances spanning 128 fault-domain classes, the full CONTINUITY configuration commits no harmful external effect, while completing all 700 benign tasks and escalating all 200 ambiguous cases. These results show that secure agent execution requires not only sound individual controls, but explicit contracts that preserve their guarantees across the complete instruction-to-effect path.

补充信息

↑