计算受限的安全保障——资源约束下的覆盖、验证与响应
Compute-Bounded Security Assurance - Coverage, Verification, and Response under Resource Constraints
浏览论文内容
中文总结 AI 辅助
本文提出资源受限框架,区分重复成功、唯一覆盖等概念,通过理论综合与反例揭示覆盖率上限与相关性无关,并设计防御架构与评估协议,确保计算受限下的安全保障。
中文摘要 AI 辅助
额外的推理计算可以增加正确解决的安全保障任务数量,但重复成功、唯一覆盖、被接受的证据和运营保护是不同的量。我们开发了一个资源受限的框架来区分这些概念。对于具有潜在成功概率 $\Theta$ 的重复条件独立尝试,覆盖率为 $C_n = 1 - E[(1-\Theta)^n]$,其极限值为 $1 - P(\Theta = 0)$。正的两两结果相关性本身并不暗示存在低于1的上限:我们构建了两个具有相同平均成功率和两两相关性但极限覆盖率不同的模型。我们将这一结果与用于估计均值的有效样本量区分开来,并展示了为什么有限预算的观测通常无法识别渐近支持上限。然后,我们将覆盖率与易错证据检查、事实基础的适当评分、完整资源核算、服务容量以及包含缓解延迟的响应模型联系起来。一个概念性的防御架构将证据分析、裁决和运营权限分开。一个评估协议规定了保留任务、配对比较、负例和不确定性报告。贡献在于一致的理论综合和一组针对无效外推的反例,而非经验性的扩展规律。所有数值示例均为解析性的;不声称存在模型对等结果、硬件基准或通用的攻击者-防御者均衡。
英文摘要
Additional inference compute can increase the number of correctly resolved security-assurance tasks, but repeated success, unique coverage, accepted evidence, and operational protection are different quantities. We develop a resource-constrained framework that separates them. For repeated conditionally independent attempts with latent success probability $Θ$, coverage is $C_n = 1 - E[(1-Θ)^n]$, and its limiting value is $1 - P(Θ= 0)$. Positive pairwise outcome correlation does not by itself imply a ceiling below one: we construct two models with the same mean success and pairwise correlation but different limiting coverage. We distinguish this result from the effective sample size used to estimate a mean, and show why finite-budget observations cannot generally identify an asymptotic support ceiling. We then connect coverage to fallible evidence checking, proper scoring of factual grounding, complete resource accounting, service capacity, and a response model that includes mitigation delay. A conceptual defensive architecture separates evidence analysis, adjudication, and operational authority. An evaluation protocol specifies held-out tasks, paired comparisons, negative cases, and uncertainty reporting. The contribution is a consistent theoretical synthesis and a set of counterexamples to invalid extrapolations, rather than an empirical scaling law. All numerical illustrations are analytic; no model-parity result, hardware benchmark, or general attacker-defender equilibrium is claimed.
发表机构
- Bud Ecosystem(巴德生态系统)
机构由 AI 辅助整理,请以论文原文为准。