arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

从意图到执行授权:高风险AI行动的执行边界一致性配置文件

From Intent to Execution Grant: An Execution-Boundary Conformance Profile for High-Risk AI Actions

Mengting Wu, Lin Wang, Yong Zhang, Jiang Deng

arXiv 2609.11596首次发表:更新:

发表机构

Chengdu Havenlon Security Technology Co., Ltd.(成都海文隆安全技术有限公司)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

针对AI高风险行动,提出EBL-Core执行边界一致性配置文件,通过执行释放契约规范授权决策,并验证其可执行性。

AI 中文摘要

AI智能体越来越多地提出具有外部后果的行动,包括金融转账、基础设施变更、软件部署、信息披露和物理驱动。授权引擎、策略语言、运行时监控、溯源机制和智能体护栏提供了重要的基础,但未必为从特定候选行动到执行权限的最终过渡定义共同的语义契约。我们定义了EBL-Core,一个执行边界一致性配置文件,用于决定在明确条件下,一个规范的、完全物化的AI生成候选行动是否可以接收行动范围限定的执行权限。它通过执行释放契约(ERC)绑定结构化意图对象、根策略和操作策略、证据义务、类型化证据、上下文、时间以及可验证的决策推导。ERC不是承载权限的令牌;经过验证的ALLOW ERC可以支持由赎回时验证管理的单独执行授权。EBL-Core规定了行动绑定、策略非弱化、证据处理、确定性裁决、推导验证和授权生命周期行为。随附的参考工件提供了模式、裁决、独立验证和语义重放,以及可线性化的内存授权存储。在保留的运行中,34个静态向量和15个生命周期检查与预期结果匹配。在100次试验中,32次并发赎回尝试每次恰好产生一次成功赎回并保护了测试效果;100次撤销-赎回竞争以有效的终端结果结束。这些有限的结果证明了所指定子集的可执行性,而非人类意图正确性、证据真实性、完全中介、生产就绪性、机械化正确性或部署级安全性。

英文摘要

AI agents increasingly propose actions with external consequences, including financial transfers, infrastructure changes, software deployments, disclosures, and physical actuation. Authorization engines, policy languages, runtime monitors, provenance mechanisms, and agent guardrails provide important foundations, but do not necessarily define a common semantic contract for the final transition from a particular candidate action to execution authority. We specify EBL-Core, an execution-boundary conformance profile for deciding whether one canonical, fully materialized AI-generated candidate may receive action-scoped execution authority under explicit conditions. It binds a structured intent object, Root and Operational Policies, evidence obligations, typed evidence, context, time, and a verifiable Decision Derivation through an Execution Release Contract (ERC). An ERC is not an authority-bearing token; a verified ALLOW ERC may support a separate Execution Grant governed by Redemption-time validation. EBL-Core specifies action binding, policy non-weakening, evidence handling, deterministic adjudication, derivation verification, and grant lifecycle behavior. An accompanying reference artifact provides schemas, adjudication, separate verification and Semantic Replay, and a linearizable in-memory grant store. In the retained run, 34 static vectors and 15 lifecycle checks matched expected outcomes. Across 100 trials, 32 concurrent Redemption attempts yielded exactly one successful Redemption and protected test effect per trial; 100 Revoke-Redeem races ended in valid terminal outcomes. These bounded results demonstrate executability of the specified subset, not human-intent correctness, evidence truth, complete mediation, production readiness, mechanized correctness, or deployment-level security.

Comments28 pages, 2 figures, 8 tables. Includes an ancillary minimal reference artifact with schemas, test vectors, and executable validation

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑