arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

AcquireBound:AI智能体获取资源的运行时授权

Runtime Authorization for Resources Acquired by AI Agents

Genliang Zhu, Chu Wang

arXiv 2609.14744首次发表:更新:

发表机构

Accentrust; Georgia Institute of Technology(Accentrust; 佐治亚理工学院)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

针对AI智能体获取资源后可能产生未授权权限的问题,提出AcquireBound运行时授权架构,通过来源约束、能力解析和激活交易确保安全,实验验证了其有效性和可靠性。

AI 中文摘要

自主AI智能体通过获取计算资源、凭证、账户、服务及其他智能体,可能为任务引入新的权限。支付、预算、OAuth、授权和履约检查可以验证交易条件,但无法决定返回的资源是否可能成为可用的权限。这种履约后激活缺口跨越了工具介导的创建、智能体间委托和智能体商务。我们提出AcquireBound,一种基于来源约束的运行时授权架构。它将获取的输出隔离,通过版本化解析器从经过认证的提供者证据中解析其实际能力,并仅通过当前激活交易激活它们,该交易检查解析的清单、来源、纪元以及类型化资源-能力超图上的向下封闭关系包络。该包络保留关联的身份、效果、数据、委托和图范围限制。单次使用效果许可在效果线性化时重新验证并消耗。在明确假设下,我们证明了八项安全属性,涵盖隔离、支持、非放大、分裂规避、崩溃/重试、退款、纪元及效果限制。在五类资源中,参考语义接受了20/20个良性轨迹,并在810个事件中拒绝了40/40个已注册的不安全轨迹;独立检查器在60个基础和40个细化轨迹上达成一致,并拒绝了89/89个篡改测试。冻结的Codex和Gemini模型上下文协议(MCP)客户端组件完成了54/54次确定性本地stdio调用。在注册的18例分阶段MCP到Docker组合中,两个良性路径均完成,16个不安全路径均未添加未经授权的Docker启动请求。五来源审计对32个单元中的1,248个字段对进行了分类;没有单一单元单独提供完整的激活配置文件。

英文摘要

By acquiring compute, credentials, accounts, services, and other agents, autonomous AI agents can introduce new authority into a task. Payment, budget, OAuth, mandate, and fulfillment checks can validate transaction conditions without deciding whether a returned resource may become usable authority. This post-fulfillment activation gap spans tool-mediated creation, inter-agent delegation, and agentic commerce. We present a provenance-bounded runtime authorization architecture. It quarantines acquired outputs, resolves their actual capabilities from authenticated provider evidence through a versioned resolver, and activates them only through a current activation transaction that checks the resolved manifest, provenance, epochs, and a downward-closed relational envelope over a typed resource-capability hypergraph. The envelope preserves correlated identity, effect, data, delegation, and graph-wide limits. Single-use effect permits are revalidated and consumed at effect linearization. Under explicit assumptions, we prove eight safety properties covering quarantine, backing, non-amplification, split non-evasion, crash/retry, refunds, epochs, and effect confinement. Across five resource classes, reference semantics accepted 20/20 benign traces and rejected 40/40 registered unsafe traces over 810 events; an independent checker agreed on 60 base and 40 refinement traces and rejected 89/89 tamper tests. Frozen Codex and Gemini Model Context Protocol (MCP) client components completed 54/54 deterministic local stdio calls. In a registered 18-case staged MCP-to-Docker composition, both benign paths completed, and none of the 16 unsafe paths added an unauthorized Docker start request. A five-source audit classified 1,248 field pairs across 32 units; no unit alone supplied a complete activation profile.

Comments55 pages, 1 figure, 9 tables, 4 algorithms. Revised title and terminology to use standard descriptive language; added Chu Wang as coauthor; strengthened the peer-reviewed literature grounding; technical results unchanged

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑