arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

反蜂群学说:遏制协调式智能体入侵

Counter-Swarm Doctrine: Containing Coordinated Agent Intrusions

Gregory N Frank

arXiv 2609.06140首次发表:更新:

发表机构

MoltAI Corp(MoltAI公司)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

针对智能体利用共享基础设施进行协调入侵的问题,提出以可修订协调片段为防御单元,通过前瞻性片段发现方法,并设计评估方案,为跨执行监控提供可测试建议。

AI 中文摘要

智能体可以将共享基础设施转变为协调入侵的渠道。Hugging Face事件以及一项独立的公共维基调查表明,安全评估可能需要来自多次执行及其遗留痕迹的证据。我们认为,防御的运作单元应是一个可修订的协调片段,该片段将观察到的转移、任务权限和响应历史关联起来。核心研究问题是前瞻性片段发现:即在评估者提供成员归属之前,找出哪些行动属于同一片段。我们相对于协作和授权策略定义了未经批准的协调,将存储介导的协调与stigmergy(间接协作机制)联系起来,并明确了区分影响与共同原因所需的证据。首触信号是发现的一种可能输入;该设计还遵循继承状态和后续使用。一项拟议的评估在匹配的审查成本和误报工作量下,比较了孤立行动、滚动窗口、已知群体和前瞻性发现的片段。它衡量所有指定群体运行中的有害结果,并测试通道关闭和状态隔离后的复发情况。对公共维基导出的校验和验证重建,区分了保留写入的下降与后续管理清理。贡献在于一个基于事件的立场、描述性分析和评估设计。它使跨执行监控的建议可测试,而不声称新检测器或可测量的遏制收益。

英文摘要

Agents can turn shared infrastructure into a channel for coordinated intrusion. The Hugging Face incident and a separate public-wiki investigation show why a security assessment may need evidence from several executions and the artifacts they leave behind. We argue that the operational unit of defence should be a revisable coordination episode linking observed transfers, task authority, and response history. The central research problem is prospective episode discovery: finding which actions belong together before an evaluator supplies their membership. We define unsanctioned coordination relative to collaboration and delegated-authority policy, connect storage-mediated coordination to stigmergy, and specify the evidence needed to distinguish influence from common causes. First-contact signals are one possible input to discovery; the design also follows inherited state and later use. A proposed evaluation compares isolated actions, rolling windows, known groups, and prospectively discovered episodes at matched review cost and false-alert workload. It measures harmful outcomes across all assigned population runs and tests recurrence after channel closure and state quarantine. A checksum-verified reconstruction of the public wiki export separates the decline in retained writes from later administrative cleanup. The contribution is an incident-grounded position, descriptive analysis, and evaluation design. It makes the recommendation to monitor across executions testable without claiming a new detector or a measured containment benefit.

Comments35 pages, 5 figures, 12 tables

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑