NovaFabric:自主AI智能体运行的可防篡改、可重放证据
NovaFabric: Tamper-Evident, Replayable Evidence for Autonomous AI Agent Runs
浏览论文内容
中文总结 AI 辅助
NovaFabric通过运行胶囊和密封机制,为自主AI智能体提供防篡改、可重放的审计级证据,经实验验证其完整性与性能。
中文摘要 AI 辅助
当一个自主AI智能体做出有重大影响的行为时,关于其行为可以证明什么?智能体可观测性平台捕获轨迹,但轨迹是可变的:可在不被察觉的情况下被篡改,没有重新执行它的方法,也无法说明捕获的机密是否已被移除。法规(欧盟AI法案、ISO 42001、NIST AI RMF)假定存在独立方可以核查的记录。我们提出NovaFabric,生成审计级执行证据:供应商中立、防篡改、可重放、可共享。它在不修改智能体逻辑的情况下,将智能体运行记录到便携式运行胶囊(十五实体模式)中,并使用整体DSSE签名、RFC 3161时间戳、Merkle日志和编辑证明进行密封。密封的运行可在四模式重放协议下重新执行,并可导出为证据包,供第三方使用现成工具(已指定,未评估)进行验证。其贡献在于集成而非新密码学:OpenTelemetry、DSSE/in-toto和W3C PROV。我们在测量范围内评估了八个研究问题。模拟重放从胶囊中提供每个模型响应(无实时模型调用,10/10),但相对于模型是离线的,而非相对于网络;只有2/10的工具使用工作负载完成;差距在于缺少工具响应替换。在三个测试类别中,篡改均被拒绝。声明流完整性为0.652(95%置信区间±0.064,十个场景)。修复后的规则包编辑了14/14种凭据类型,保留了9/9个诱饵;差异定位了140/140个突变。爆炸半径查询:在1000万条边上p99为45.5毫秒(比列式基线快3.3倍),在1亿条边上为167.9毫秒(1个客户端,n=30)。一个314台机器、十个区域的运行发现胶囊REST摄取无丢失,但受限于61.6请求/秒(p99为26.8秒),原因是每工作线程串行化。在NovaFabric及其评估语料库中发现了六个缺陷:四个已修复,一个已撤回,一个未解决。验证以所述可信计算基为条件。
英文摘要
When an autonomous AI agent does something consequential, what can be proven about what it did? Agent-observability platforms capture traces, but a trace is mutable: alterable undetected, with no recipe for re-executing it, silent on whether captured secrets were removed. Regulation (EU AI Act, ISO 42001, NIST AI RMF) presumes records an independent party can check. We present NovaFabric, producing audit-grade execution evidence: provider-neutral, tamper-evident, replayable, shareable. It records an agent run, without modifying agent logic, into a portable Run Capsule (fifteen-entity schema), sealed with a holistic DSSE signature, RFC 3161 timestamp, Merkle log and redaction attestation. Sealed runs are re-executable under a four-mode replay protocol and exportable as an Evidence Bundle for third-party verification with stock tooling (specified, not evaluated). The contribution is integration, not new cryptography: OpenTelemetry, DSSE/in-toto and W3C PROV. We evaluate eight research questions at measured scope. Mocked replay serves every model response from the capsule (no live model call, 10/10) but is offline w.r.t. models, not the network; only 2/10 tool-using workloads completed; the gap is missing tool-response substitution. Tampering is rejected across three tested classes. Declared-stream completeness is 0.652 (95% CI +/-0.064, ten scenarios). A repaired rule pack redacts 14/14 credential types, preserving 9/9 decoys; diff localises 140/140 mutations. Blast-radius queries: 45.5ms p99 over 10M edges (3.3x faster than a columnar baseline), 167.9ms over 100M (1 client, n=30). A 314-machine, ten-region run finds capsule REST ingest lossless but capped at 61.6 req/s (p99 26.8s) by per-worker serialisation. Six defects found in NovaFabric and its evaluation corpus: four fixed, one withdrawn, one open. Verification is conditional on a stated trusted computing base.